CVE-2021-21972: vCenter Server RCE
A remote code execution vulnerability in the vSphere Client's vRealize Operations plugin for VMware vCenter Server. An unauthenticated attacker with network access to port 443 can upload a crafted file and execute commands with unrestricted privileges on the underlying operating system.
View the authoritative record on NVD ↗Affected software
- vCenter Server 6.5
- vCenter Server 6.7
- vCenter Server 7.0
How it's exploited
Send a crafted HTTP POST request to the vulnerable vRealize Operations plugin endpoint in the vSphere Client, which fails to validate the destination path, writing an attacker-controlled file to a location the server later executes from.
Severity
CVE-2021-21972 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2021-21972 is categorized under CWE-22, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Path Traversal using OWASP ZAP and Nuclei and FFUF, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 9 dedicated rules for this weakness.
Tools: OWASP ZAP, Nuclei, FFUF
Remediation
Apply the VMware-published patch (VMSA-2021-0002) for the affected vCenter Server version, or the documented workaround of disabling the vulnerable plugin if patching must wait.
Frequently asked questions
What is CVE-2021-21972?
A remote code execution vulnerability in the vSphere Client's vRealize Operations plugin for VMware vCenter Server. An unauthenticated attacker with network access to port 443 can upload a crafted file and execute commands with unrestricted privileges on the underlying operating system.
How severe is CVE-2021-21972?
CVE-2021-21972 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2021-21972?
CVE-2021-21972 affects vCenter Server 6.5; vCenter Server 6.7; vCenter Server 7.0.
How do you fix CVE-2021-21972?
Apply the VMware-published patch (VMSA-2021-0002) for the affected vCenter Server version, or the documented workaround of disabling the vulnerable plugin if patching must wait.
Where is the authoritative record for CVE-2021-21972?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2021-21972 at https://nvd.nist.gov/vuln/detail/CVE-2021-21972, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
- CVSS 7.5 HighCVE-2021-41773: Apache HTTP Server Path Traversal
- CVSS 9.8 CriticalCVE-2019-19781: Citrix ADC Path Traversal RCE
- CVSS 10.0 CriticalCVE-2019-11510: Pulse Secure Arbitrary File Read
- CVSS 9.8 CriticalCVE-2018-13379: FortiOS SSL VPN Path Traversal
- CVSS 10.0 CriticalCVE-2021-44228: Log4Shell
- CVSS 9.8 CriticalCVE-2021-26855: ProxyLogon
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest