VMware vCenter Server Improper Input Validation Vulnerability
Critical CVSS 9.8 Listed in CISA KEV
Summary
VMware vSphere Client contains an improper input validation vulnerability in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server, which allows for remote code execution.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- VMware:vCenter Server
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2021-21985 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- http://packetstormsecurity.com/files/162812/VMware-Security-Advisory-2021-0010.html Third Party Advisory
- http://packetstormsecurity.com/files/163487/VMware-vCenter-Server-Virtual-SAN-Health-Check-Remote-Code-Execution.html Exploit
- https://www.vmware.com/security/advisories/VMSA-2021-0010.html Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21985 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD