CVE-2021-21973

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vmwareCNA
---
---
CVEADP
---
---
CISA-ADPADP
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
vmwarecloud_foundation
3.0 ≤
𝑥
< 3.10.1.2
vmwarecloud_foundation
4.0 ≤
𝑥
< 4.2
vmwarevcenter_server
6.5
vmwarevcenter_server
6.5:a
vmwarevcenter_server
6.5:b
vmwarevcenter_server
6.5:c
vmwarevcenter_server
6.5:d
vmwarevcenter_server
6.5:e
vmwarevcenter_server
6.5:f
vmwarevcenter_server
6.5:update1d
vmwarevcenter_server
6.5:update1e
vmwarevcenter_server
6.5:update1g
vmwarevcenter_server
6.5:update2
vmwarevcenter_server
6.5:update2b
vmwarevcenter_server
6.5:update2c
vmwarevcenter_server
6.5:update2d
vmwarevcenter_server
6.5:update2g
vmwarevcenter_server
6.5:update3
vmwarevcenter_server
6.5:update3d
vmwarevcenter_server
6.5:update3f
vmwarevcenter_server
6.5:update3k
vmwarevcenter_server
6.7
vmwarevcenter_server
6.7:a
vmwarevcenter_server
6.7:b
vmwarevcenter_server
6.7:d
vmwarevcenter_server
6.7:update1
vmwarevcenter_server
6.7:update1b
vmwarevcenter_server
6.7:update2
vmwarevcenter_server
6.7:update2a
vmwarevcenter_server
6.7:update2c
vmwarevcenter_server
6.7:update3
vmwarevcenter_server
6.7:update3a
vmwarevcenter_server
6.7:update3b
vmwarevcenter_server
6.7:update3f
vmwarevcenter_server
6.7:update3g
vmwarevcenter_server
6.7:update3j
vmwarevcenter_server
7.0
vmwarevcenter_server
7.0:a
vmwarevcenter_server
7.0:b
vmwarevcenter_server
7.0:c
vmwarevcenter_server
7.0:d
vmwarevcenter_server
7.0:update1
vmwarevcenter_server
7.0:update1a
𝑥
= Vulnerable software versions