CVE-2021-22005
CRITICAL9.8Path traversalCISA KEVRansomwarePublic PoCTrendingHigh EPSS
Description
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Exploits & proofs of concept
- nucleiVMware Detectionby elouhi
- nucleiVMware vCenter Server - Arbitrary File Uploadby PR3R00T