CVE-2021-21973
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Record summary
CVE-2021-21973 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC and 1 Nuclei template. CISA lists CVE-2021-21973 in KEV.
Description
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Exploitation context
Known exploitation
- CISA KEV
- Listed · Mar 7, 2022 · CISA
- VulnCheck KEV
- Listed · Feb 25, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 16, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
vCenter Server and Cloud FoundationBrowse VMware / vCenter Server and Cloud Foundation | CISA | Version data not supplied | |
VMware Cloud Foundation | CVE List | 4.x before 4.2 | affected |
| 3.x before 3.10.1.2 | affected | ||
VMware vCenter Server | CVE List | 7.x before 7.0 U1c | affected |
| 6.7 before 6.7 U3l | affected | ||
| 6.5 before 6.5 U3n | affected | ||
Proofs of concept
1Repository PoCs
GitHubfreakanonymous/CVE-2021-21973-AutomatemeRepository PoCby freakanonymousStars: 1Not analyzed3 files
Nuclei templates
1ProjectDiscoveryMEDIUMVMware vSphere - Server-Side Request ForgeryCVSS 5.3
VMware vSphere (HTML5) is susceptible to server-side request forgery due to improper validation of URLs in a vCenter Server plugin. An attacker with network access to port 443 can exploit this issue by sending a POST request to the plugin. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l, and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Impact
Successful exploitation of this vulnerability could allow an attacker to send arbitrary requests from the vulnerable server, potentially leading to unauthorized access, data leakage, or further attacks.
Remediation
Apply the necessary security patches or updates provided by VMware to mitigate this vulnerability.
Source: ProjectDiscovery