CyberSec.Space Logo
CVEブラウザに戻る

CVE-2021-21985

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score95.8860%
EPSS Percentile95.73th
Published2021-05-26
Last Modified2025-10-30
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Affected Platforms (CPE)

📦
Vmware

Vcenter Server

= 6.5= 6.7= 7.0
📦
Vmware

Cloud Foundation

>= 3.0 and < 3.10.2.1>= 4.0 and < 4.2.1

References & Advisories

関連するセキュリティ記事

関連する脆弱性情報