CVE-2021-21976

EUVD-2021-9147
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a remote code execution.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 81%
Affected Products (NVD)
VendorProductVersion
vmwarevsphere_replication
6.5.0 ≤
𝑥
< 6.5.1.5
vmwarevsphere_replication
8.1.0 ≤
𝑥
< 8.1.2.3
vmwarevsphere_replication
8.2.0 ≤
𝑥
< 8.2.1.1
vmwarevsphere_replication
8.3.0 ≤
𝑥
< 8.3.1.2
𝑥
= Vulnerable software versions