CVE Vulnerabilities

CVE-2021-22014

Published: Sep 23, 2021 | Modified: Sep 27, 2021
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.

Affected Software

Name Vendor Start Version End Version
Cloud_foundation Vmware 3.0 (including) 5.0 (excluding)
Vcenter_server Vmware 6.5 (including) 6.5 (including)
Vcenter_server Vmware 6.7 (including) 6.7 (including)
Vcenter_server Vmware 7.0 (including) 7.0 (including)

References