26/5/2021
3/8/2024
CVE-2021-21986
First published: Wed May 26 2021(Updated: )
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability plug-ins. A malicious actor with network access to port 443 on vCenter Server may perform actions allowed by the impacted plug-ins without authentication.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|
VMware vCenter Server | =6.5 | |
VMware vCenter Server | =6.5-a | |
VMware vCenter Server | =6.5-b | |
VMware vCenter Server | =6.5-c | |
VMware vCenter Server | =6.5-d | |
VMware vCenter Server | =6.5-e | |
VMware vCenter Server | =6.5-f | |
VMware vCenter Server | =6.5-update1 | |
VMware vCenter Server | =6.5-update1b | |
VMware vCenter Server | =6.5-update1c | |
VMware vCenter Server | =6.5-update1d | |
VMware vCenter Server | =6.5-update1e | |
VMware vCenter Server | =6.5-update1g | |
VMware vCenter Server | =6.5-update2 | |
VMware vCenter Server | =6.5-update2b | |
VMware vCenter Server | =6.5-update2c | |
VMware vCenter Server | =6.5-update2d | |
VMware vCenter Server | =6.5-update2g | |
VMware vCenter Server | =6.5-update3 | |
VMware vCenter Server | =6.5-update3d | |
VMware vCenter Server | =6.5-update3f | |
VMware vCenter Server | =6.5-update3k | |
VMware vCenter Server | =6.5-update3n | |
VMware vCenter Server | =6.7 | |
VMware vCenter Server | =6.7-a | |
VMware vCenter Server | =6.7-b | |
VMware vCenter Server | =6.7-d | |
VMware vCenter Server | =6.7-update1 | |
VMware vCenter Server | =6.7-update1b | |
VMware vCenter Server | =6.7-update2 | |
VMware vCenter Server | =6.7-update2a | |
VMware vCenter Server | =6.7-update2c | |
VMware vCenter Server | =6.7-update3 | |
VMware vCenter Server | =6.7-update3a | |
VMware vCenter Server | =6.7-update3b | |
VMware vCenter Server | =6.7-update3f | |
VMware vCenter Server | =6.7-update3g | |
VMware vCenter Server | =6.7-update3j | |
VMware vCenter Server | =6.7-update3l | |
VMware vCenter Server | =6.7-update3m | |
VMware vCenter Server | =7.0 | |
VMware vCenter Server | =7.0-a | |
VMware vCenter Server | =7.0-b | |
VMware vCenter Server | =7.0-c | |
VMware vCenter Server | =7.0-d | |
VMware vCenter Server | =7.0-update1 | |
VMware vCenter Server | =7.0-update1a | |
VMware vCenter Server | =7.0-update1c | |
VMware vCenter Server | =7.0-update1d | |
VMware vCenter Server | =7.0-update2 | |
VMware vCenter Server | =7.0-update2a | |
VMware Cloud Foundation | >=3.0<3.10.2.1 | |
VMware Cloud Foundation | >=4.0<4.2.1 | |
Never miss a vulnerability like this again
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Frequently Asked Questions
What is CVE-2021-21986?
CVE-2021-21986 refers to a vulnerability in the vSphere Client (HTML5) authentication mechanism for certain VMware plugins.
Which software versions are affected by CVE-2021-21986?
CVE-2021-21986 affects VMware vCenter Server versions 6.5, 6.7, and 7.0, as well as VMware Cloud Foundation versions 3.x and 4.x.
What is the severity of CVE-2021-21986?
CVE-2021-21986 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2021-21986?
To fix CVE-2021-21986, it is recommended to upgrade to the latest version of vCenter Server or VMware Cloud Foundation, as specified in the VMware Security Advisory.
Where can I find more information about CVE-2021-21986?
You can find more information about CVE-2021-21986 in the VMware Security Advisory and the Packet Storm Security website.
- collector/nvd-index
- agent/severity
- agent/references
- agent/weakness
- agent/author
- agent/description
- agent/event
- agent/type
- agent/last-modified-date
- agent/softwarecombine
- agent/first-publish-date
- agent/tags
- collector/mitre-cve
- source/MITRE
- vendor/vmware
- canonical/vmware vcenter server
- version/vmware vcenter server/6.5
- version/vmware vcenter server/6.5-a
- version/vmware vcenter server/6.5-b
- version/vmware vcenter server/6.5-c
- version/vmware vcenter server/6.5-d
- version/vmware vcenter server/6.5-e
- version/vmware vcenter server/6.5-f
- version/vmware vcenter server/6.5-update1
- version/vmware vcenter server/6.5-update1b
- version/vmware vcenter server/6.5-update1c
- version/vmware vcenter server/6.5-update1d
- version/vmware vcenter server/6.5-update1e
- version/vmware vcenter server/6.5-update1g
- version/vmware vcenter server/6.5-update2
- version/vmware vcenter server/6.5-update2b
- version/vmware vcenter server/6.5-update2c
- version/vmware vcenter server/6.5-update2d
- version/vmware vcenter server/6.5-update2g
- version/vmware vcenter server/6.5-update3
- version/vmware vcenter server/6.5-update3d
- version/vmware vcenter server/6.5-update3f
- version/vmware vcenter server/6.5-update3k
- version/vmware vcenter server/6.5-update3n
- version/vmware vcenter server/6.7
- version/vmware vcenter server/6.7-a
- version/vmware vcenter server/6.7-b
- version/vmware vcenter server/6.7-d
- version/vmware vcenter server/6.7-update1
- version/vmware vcenter server/6.7-update1b
- version/vmware vcenter server/6.7-update2
- version/vmware vcenter server/6.7-update2a
- version/vmware vcenter server/6.7-update2c
- version/vmware vcenter server/6.7-update3
- version/vmware vcenter server/6.7-update3a
- version/vmware vcenter server/6.7-update3b
- version/vmware vcenter server/6.7-update3f
- version/vmware vcenter server/6.7-update3g
- version/vmware vcenter server/6.7-update3j
- version/vmware vcenter server/6.7-update3l
- version/vmware vcenter server/6.7-update3m
- version/vmware vcenter server/7.0
- version/vmware vcenter server/7.0-a
- version/vmware vcenter server/7.0-b
- version/vmware vcenter server/7.0-c
- version/vmware vcenter server/7.0-d
- version/vmware vcenter server/7.0-update1
- version/vmware vcenter server/7.0-update1a
- version/vmware vcenter server/7.0-update1c
- version/vmware vcenter server/7.0-update1d
- version/vmware vcenter server/7.0-update2
- version/vmware vcenter server/7.0-update2a
- canonical/vmware cloud foundation
- version/vmware cloud foundation/3.0
- version/vmware cloud foundation/4.0
Contact
SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.coBy using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203