CyberSec.Space Logo
Back to CVE Browser

CVE-2021-22005

πŸ”₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score25.7160%
EPSS Percentile92.12th
Published2021-09-23
Last Modified2025-10-30
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

Affected Platforms (CPE)

πŸ“¦
Vmware

Cloud Foundation

>= 3.0 and < 5.0
πŸ“¦
Vmware

Vcenter Server

= 6.5= 6.7= 7.0

References & Advisories

Related Security Intelligence Articles

Related Vulnerabilities