Vulnerability Name:

CVE-2021-21972 (CCN-197192)

Assigned:2021-02-23
Published:2021-02-23
Updated:2022-07-12
Summary:The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
9.1 Critical (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
9.1 Critical (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-22
CWE-306
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2021-21972

Source: MISC
Type: Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html

Source: MISC
Type: Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html

Source: MISC
Type: Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html

Source: XF
Type: UNKNOWN
vmware-vcenter-cve202121972-code-exec(197192)

Source: CCN
Type: GitHub Web site
CVE-2021-21972

Source: CCN
Type: Packet Storm Security [02-24-2021]
VMware vCenter 6.5 / 7.0 Remote Code Execution Proof Of ConceptVMware vCenter 6.5 / 7.0 Remote Code Execution Proof Of Concept

Source: CCN
Type: Packet Storm Security [03-01-2021]
VMware vCenter Server 7.0 Arbitrary File Upload

Source: CCN
Type: Packet Storm Security [03-08-2021]
VMware vCenter Server File Upload / Remote Code Execution

Source: CCN
Type: Packet Storm Security [06-24-2021]
VMware vCenter 6.5 / 6.7 / 7.0 Remote Code Execution

Source: CCN
Type: PT SWARM Web site
Unauthorized RCE in VMware vCenter

Source: CCN
Type: CYBERSECURITY & INFRASTRUCTURE SECURITY AGENCY
KNOWN EXPLOITED VULNERABILITIES CATALOG

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [03-01-2021]

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [06-24-2021]

Source: CCN
Type: IBM Security Bulletin 6485985 (Cloud Pak System)
Multiple vulnerabilities in VMware affect IBM Cloud Pak System

Source: CCN
Type: Rapid7 Vulnerability and Exploit Database [03/08/2021]
VMware vCenter Server Unauthenticated OVA File Upload RCE

Source: CCN
Type: VMware Security Advisory VMSA-2021-0002
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)

Source: CONFIRM
Type: Vendor Advisory
https://www.vmware.com/security/advisories/VMSA-2021-0002.html

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vmware:vcenter_server:6.5:f:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:e:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*
  • OR cpe:/a:vmware:cloud_foundation:*:*:*:*:*:*:*:* (Version >= 3.0 and < 3.10.1.2)
  • OR cpe:/a:vmware:cloud_foundation:*:*:*:*:*:*:*:* (Version >= 4.0 and < 4.2)
  • OR cpe:/a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update3k:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update3:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update3a:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update3b:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update3f:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update3g:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:update3j:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:vmware:vcenter_server:6.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:6.7:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_pak_system:2.3.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_system:2.3.3.3:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_system:2.3.0.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    vmware vcenter server 6.5 f
    vmware vcenter server 6.5 e
    vmware vcenter server 6.5 d
    vmware vcenter server 6.5 c
    vmware vcenter server 6.5 b
    vmware vcenter server 6.5 a
    vmware vcenter server 6.7 d
    vmware vcenter server 6.7 b
    vmware vcenter server 6.7 a
    vmware cloud foundation *
    vmware cloud foundation *
    vmware vcenter server 6.5 -
    vmware vcenter server 6.5 update1d
    vmware vcenter server 6.5 update1e
    vmware vcenter server 6.5 update1g
    vmware vcenter server 6.5 update2
    vmware vcenter server 6.5 update2b
    vmware vcenter server 6.5 update3
    vmware vcenter server 6.5 update3d
    vmware vcenter server 6.5 update3f
    vmware vcenter server 6.5 update3k
    vmware vcenter server 6.7 -
    vmware vcenter server 7.0 -
    vmware vcenter server 7.0 a
    vmware vcenter server 7.0 b
    vmware vcenter server 7.0 c
    vmware vcenter server 7.0 d
    vmware vcenter server 6.5 update2c
    vmware vcenter server 6.5 update2d
    vmware vcenter server 6.5 update2g
    vmware vcenter server 6.7 update1
    vmware vcenter server 6.7 update1b
    vmware vcenter server 6.7 update2
    vmware vcenter server 6.7 update2a
    vmware vcenter server 6.7 update2c
    vmware vcenter server 6.7 update3
    vmware vcenter server 6.7 update3a
    vmware vcenter server 6.7 update3b
    vmware vcenter server 6.7 update3f
    vmware vcenter server 6.7 update3g
    vmware vcenter server 6.7 update3j
    vmware vcenter server 7.0 update1
    vmware vcenter server 7.0 update1a
    vmware vcenter server 6.5
    vmware vcenter server 6.7
    vmware vcenter server 7.0 -
    ibm cloud pak system 2.3.3.0
    ibm cloud pak system 2.3.3.3
    ibm cloud pak system 2.3.0.0