Record summary

CVE-2021-21973 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2021-21973 in KEV.

Description

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · Mar 7, 2022 · CISA
VulnCheck KEV
Listed · Feb 25, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 16, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

vCenter Server and Cloud Foundation

Browse VMware / vCenter Server and Cloud Foundation
CISAVersion data not supplied

VMware Cloud Foundation

CVE List4.x before 4.2affected
3.x before 3.10.1.2affected

VMware vCenter Server

CVE List7.x before 7.0 U1caffected
6.7 before 6.7 U3laffected
6.5 before 6.5 U3naffected

Proofs of concept

1

Repository PoCs

GitHubfreakanonymous/CVE-2021-21973-AutomatemeRepository PoCby freakanonymousStars: 1Not analyzed3 files

36.7 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMVMware vSphere - Server-Side Request ForgeryCVSS 5.3

VMware vSphere (HTML5) is susceptible to server-side request forgery due to improper validation of URLs in a vCenter Server plugin. An attacker with network access to port 443 can exploit this issue by sending a POST request to the plugin. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l, and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Impact

Successful exploitation of this vulnerability could allow an attacker to send arbitrary requests from the vulnerable server, potentially leading to unauthorized access, data leakage, or further attacks.

Remediation

Apply the necessary security patches or updates provided by VMware to mitigate this vulnerability.

WeaknessesCWE-918
Authorspdteam
Template tagscve2021cvevmwaressrfvcenteroastkevvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3