First published: Wed Nov 24 2021(Updated: )
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware vCenter Server and Cloud Foundation | =3.0 | |
VMware vCenter | =6.5 | |
VMware vCenter | =6.5-update_1 | |
VMware vCenter | =6.5-update_1b | |
VMware vCenter | =6.5-update_1c | |
VMware vCenter | =6.5-update_1d | |
VMware vCenter | =6.5-update_1e | |
VMware vCenter | =6.5-update_1g | |
VMware vCenter | =6.5-update_2 | |
VMware vCenter | =6.5-update_2b | |
VMware vCenter | =6.5-update_2c | |
VMware vCenter | =6.5-update_2d | |
VMware vCenter | =6.5-update_2g | |
VMware vCenter | =6.5-update_3 | |
VMware vCenter | =6.5-update_3d | |
VMware vCenter | =6.5-update_3f | |
VMware vCenter | =6.5-update_3k | |
VMware vCenter | =6.5-update_3n | |
VMware vCenter | =6.5-update_3p | |
VMware vCenter | =6.5-update_3q | |
VMware vCenter | =6.7 | |
VMware vCenter | =6.7-update_1 | |
VMware vCenter | =6.7-update_1b | |
VMware vCenter | =6.7-update_2 | |
VMware vCenter | =6.7-update_2a | |
VMware vCenter | =6.7-update_2c | |
VMware vCenter | =6.7-update_3 | |
VMware vCenter | =6.7-update_3a | |
VMware vCenter | =6.7-update_3b | |
VMware vCenter | =6.7-update_3f | |
VMware vCenter | =6.7-update_3g | |
VMware vCenter | =6.7-update_3j | |
VMware vCenter | =6.7-update_3l | |
VMware vCenter | =6.7-update_3m | |
VMware vCenter | =6.7-update_3n | |
VMware vCenter | =6.7-update_3o |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21980 has a critical severity rating due to the possibility of unauthorized arbitrary file read.
To fix CVE-2021-21980, it is recommended to apply the patches provided by VMware for affected versions of vCenter Server and Cloud Foundation.
CVE-2021-21980 affects VMware vCenter Server 6.5 and 6.7, as well as VMware Cloud Foundation 3.0.
Yes, CVE-2021-21980 can be exploited remotely by attackers with network access to port 443 on the vCenter Server.
Through CVE-2021-21980, an attacker can potentially gain access to sensitive information stored on the vCenter Server.