CVE-2021-21978

CRITICAL EXPLOITED NUCLEI

Vmware View Planner < 4.6 - Missing Authorization

Title source: rule

Description

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

Exploits (5)

nomisec WORKING POC 25 stars
by skytina · poc
https://github.com/skytina/CVE-2021-21978
nomisec WORKING POC 23 stars
by GreyOrder · poc
https://github.com/GreyOrder/CVE-2021-21978
nomisec WORKING POC 5 stars
by me1ons · poc
https://github.com/me1ons/CVE-2021-21978
vulncheck_xdb WORKING POC
remote
https://github.com/vvgoodman/poclist
metasploit WORKING POC EXCELLENT
by Mikhail Klyuchnikov, wvu, Grant Willcox · rubypocpython
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_view_planner_4_6_uploadlog_rce.rb

Nuclei Templates (1)

VMware View Planner <4.6 SP1- Remote Code Execution
CRITICALby dwisiswant0

Scores

CVSS v3 9.8
EPSS 0.9050
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2023-12-03
CWE
CWE-862 CWE-20
Status published
Products (2)
vmware/view_planner 4.6
vmware/view_planner 4.0 - 4.6
Published Mar 03, 2021
Tracked Since Feb 18, 2026