CVE-2021-21980: High severity vmware vcenter server and cloud foundation vulnerability
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21980?
CVE-2021-21980 has a critical severity rating due to the possibility of unauthorized arbitrary file read.
How do I fix CVE-2021-21980?
To fix CVE-2021-21980, it is recommended to apply the patches provided by VMware for affected versions of vCenter Server and Cloud Foundation.
What software is affected by CVE-2021-21980?
CVE-2021-21980 affects VMware vCenter Server 6.5 and 6.7, as well as VMware Cloud Foundation 3.0.
Can CVE-2021-21980 be exploited remotely?
Yes, CVE-2021-21980 can be exploited remotely by attackers with network access to port 443 on the vCenter Server.
What information can be accessed through the CVE-2021-21980 vulnerability?
Through CVE-2021-21980, an attacker can potentially gain access to sensitive information stored on the vCenter Server.