First published: Tue Jul 13 2021(Updated: )
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | >=3.0<3.10.2 | |
VMware Cloud Foundation | >=4.0<4.3 | |
VMware ESXi | =6.5 | |
VMware ESXi | =6.5-650-201701001 | |
VMware ESXi | =6.5-650-201703001 | |
VMware ESXi | =6.5-650-201703002 | |
VMware ESXi | =6.5-650-201704001 | |
VMware ESXi | =6.5-650-201707101 | |
VMware ESXi | =6.5-650-201707102 | |
VMware ESXi | =6.5-650-201707103 | |
VMware ESXi | =6.5-650-201707201 | |
VMware ESXi | =6.5-650-201707202 | |
VMware ESXi | =6.5-650-201707203 | |
VMware ESXi | =6.5-650-201707204 | |
VMware ESXi | =6.5-650-201707205 | |
VMware ESXi | =6.5-650-201707206 | |
VMware ESXi | =6.5-650-201707207 | |
VMware ESXi | =6.5-650-201707208 | |
VMware ESXi | =6.5-650-201707209 | |
VMware ESXi | =6.5-650-201707210 | |
VMware ESXi | =6.5-650-201707211 | |
VMware ESXi | =6.5-650-201707212 | |
VMware ESXi | =6.5-650-201707213 | |
VMware ESXi | =6.5-650-201707214 | |
VMware ESXi | =6.5-650-201707215 | |
VMware ESXi | =6.5-650-201707216 | |
VMware ESXi | =6.5-650-201707217 | |
VMware ESXi | =6.5-650-201707218 | |
VMware ESXi | =6.5-650-201707219 | |
VMware ESXi | =6.5-650-201707220 | |
VMware ESXi | =6.5-650-201707221 | |
VMware ESXi | =6.5-650-201710001 | |
VMware ESXi | =6.5-650-201712001 | |
VMware ESXi | =6.5-650-201803001 | |
VMware ESXi | =6.5-650-201806001 | |
VMware ESXi | =6.5-650-201808001 | |
VMware ESXi | =6.5-650-201810001 | |
VMware ESXi | =6.5-650-201810002 | |
VMware ESXi | =6.5-650-201811001 | |
VMware ESXi | =6.5-650-201811002 | |
VMware ESXi | =6.5-650-201811301 | |
VMware ESXi | =6.5-650-201901001 | |
VMware ESXi | =6.5-650-201903001 | |
VMware ESXi | =6.5-650-201905001 | |
VMware ESXi | =6.5-650-201908001 | |
VMware ESXi | =6.5-650-201910001 | |
VMware ESXi | =6.5-650-20191004001 | |
VMware ESXi | =6.5-650-201911001 | |
VMware ESXi | =6.5-650-201911401 | |
VMware ESXi | =6.5-650-201911402 | |
VMware ESXi | =6.5-650-201912001 | |
VMware ESXi | =6.5-650-201912002 | |
VMware ESXi | =6.5-650-201912101 | |
VMware ESXi | =6.5-650-201912102 | |
VMware ESXi | =6.5-650-201912103 | |
VMware ESXi | =6.5-650-201912104 | |
VMware ESXi | =6.5-650-201912301 | |
VMware ESXi | =6.5-650-201912401 | |
VMware ESXi | =6.5-650-201912402 | |
VMware ESXi | =6.5-650-201912403 | |
VMware ESXi | =6.5-650-201912404 | |
VMware ESXi | =6.5-650-202005001 | |
VMware ESXi | =6.5-650-202006001 | |
VMware ESXi | =6.5-650-202007001 | |
VMware ESXi | =6.5-650-202010001 | |
VMware ESXi | =6.5-650-202011001 | |
VMware ESXi | =6.5-650-202011002 | |
VMware ESXi | =6.5-650-202102001 | |
VMware ESXi | =6.5-650-202102002 | |
VMware ESXi | =6.5-650-202102003 | |
VMware ESXi | =6.7 | |
VMware ESXi | =6.7-670-201806001 | |
VMware ESXi | =6.7-670-201807001 | |
VMware ESXi | =6.7-670-201808001 | |
VMware ESXi | =6.7-670-201810001 | |
VMware ESXi | =6.7-670-201810101 | |
VMware ESXi | =6.7-670-201810102 | |
VMware ESXi | =6.7-670-201810103 | |
VMware ESXi | =6.7-670-201810201 | |
VMware ESXi | =6.7-670-201810202 | |
VMware ESXi | =6.7-670-201810203 | |
VMware ESXi | =6.7-670-201810204 | |
VMware ESXi | =6.7-670-201810205 | |
VMware ESXi | =6.7-670-201810206 | |
VMware ESXi | =6.7-670-201810207 | |
VMware ESXi | =6.7-670-201810208 | |
VMware ESXi | =6.7-670-201810209 | |
VMware ESXi | =6.7-670-201810210 | |
VMware ESXi | =6.7-670-201810211 | |
VMware ESXi | =6.7-670-201810212 | |
VMware ESXi | =6.7-670-201810213 | |
VMware ESXi | =6.7-670-201810214 | |
VMware ESXi | =6.7-670-201810215 | |
VMware ESXi | =6.7-670-201810216 | |
VMware ESXi | =6.7-670-201810217 | |
VMware ESXi | =6.7-670-201810218 | |
VMware ESXi | =6.7-670-201810219 | |
VMware ESXi | =6.7-670-201810220 | |
VMware ESXi | =6.7-670-201810221 | |
VMware ESXi | =6.7-670-201810222 | |
VMware ESXi | =6.7-670-201810223 | |
VMware ESXi | =6.7-670-201810224 | |
VMware ESXi | =6.7-670-201810225 | |
VMware ESXi | =6.7-670-201810226 | |
VMware ESXi | =6.7-670-201810227 | |
VMware ESXi | =6.7-670-201810228 | |
VMware ESXi | =6.7-670-201810229 | |
VMware ESXi | =6.7-670-201810230 | |
VMware ESXi | =6.7-670-201810231 | |
VMware ESXi | =6.7-670-201810232 | |
VMware ESXi | =6.7-670-201810233 | |
VMware ESXi | =6.7-670-201810234 | |
VMware ESXi | =6.7-670-201811001 | |
VMware ESXi | =6.7-670-201901001 | |
VMware ESXi | =6.7-670-201901401 | |
VMware ESXi | =6.7-670-201901402 | |
VMware ESXi | =6.7-670-201901403 | |
VMware ESXi | =6.7-670-201903001 | |
VMware ESXi | =6.7-670-201904001 | |
VMware ESXi | =6.7-670-201904201 | |
VMware ESXi | =6.7-670-201904201-ug | |
VMware ESXi | =6.7-670-201904202 | |
VMware ESXi | =6.7-670-201904202-ug | |
VMware ESXi | =6.7-670-201904203 | |
VMware ESXi | =6.7-670-201904203-ug | |
VMware ESXi | =6.7-670-201904204 | |
VMware ESXi | =6.7-670-201904204-ug | |
VMware ESXi | =6.7-670-201904205 | |
VMware ESXi | =6.7-670-201904205-ug | |
VMware ESXi | =6.7-670-201904206 | |
VMware ESXi | =6.7-670-201904206-ug | |
VMware ESXi | =6.7-670-201904207 | |
VMware ESXi | =6.7-670-201904207-ug | |
VMware ESXi | =6.7-670-201904208 | |
VMware ESXi | =6.7-670-201904208-ug | |
VMware ESXi | =6.7-670-201904209 | |
VMware ESXi | =6.7-670-201904209-ug | |
VMware ESXi | =6.7-670-201904210 | |
VMware ESXi | =6.7-670-201904210-ug | |
VMware ESXi | =6.7-670-201904211 | |
VMware ESXi | =6.7-670-201904211-ug | |
VMware ESXi | =6.7-670-201904212 | |
VMware ESXi | =6.7-670-201904212-ug | |
VMware ESXi | =6.7-670-201904213 | |
VMware ESXi | =6.7-670-201904213-ug | |
VMware ESXi | =6.7-670-201904214 | |
VMware ESXi | =6.7-670-201904214-ug | |
VMware ESXi | =6.7-670-201904215 | |
VMware ESXi | =6.7-670-201904215-ug | |
VMware ESXi | =6.7-670-201904216 | |
VMware ESXi | =6.7-670-201904216-ug | |
VMware ESXi | =6.7-670-201904217 | |
VMware ESXi | =6.7-670-201904217-ug | |
VMware ESXi | =6.7-670-201904218 | |
VMware ESXi | =6.7-670-201904218-ug | |
VMware ESXi | =6.7-670-201904219 | |
VMware ESXi | =6.7-670-201904219-ug | |
VMware ESXi | =6.7-670-201904220 | |
VMware ESXi | =6.7-670-201904220-ug | |
VMware ESXi | =6.7-670-201904221 | |
VMware ESXi | =6.7-670-201904221-ug | |
VMware ESXi | =6.7-670-201904222 | |
VMware ESXi | =6.7-670-201904222-ug | |
VMware ESXi | =6.7-670-201904223 | |
VMware ESXi | =6.7-670-201904223-ug | |
VMware ESXi | =6.7-670-201904224 | |
VMware ESXi | =6.7-670-201904224-ug | |
VMware ESXi | =6.7-670-201904225 | |
VMware ESXi | =6.7-670-201904225-ug | |
VMware ESXi | =6.7-670-201904226 | |
VMware ESXi | =6.7-670-201904226-ug | |
VMware ESXi | =6.7-670-201904227 | |
VMware ESXi | =6.7-670-201904227-ug | |
VMware ESXi | =6.7-670-201904228 | |
VMware ESXi | =6.7-670-201904228-ug | |
VMware ESXi | =6.7-670-201904229 | |
VMware ESXi | =6.7-670-201904229-ug | |
VMware ESXi | =6.7-670-201905001 | |
VMware ESXi | =6.7-670-201906002 | |
VMware ESXi | =6.7-670-201908101 | |
VMware ESXi | =6.7-670-201908102 | |
VMware ESXi | =6.7-670-201908103 | |
VMware ESXi | =6.7-670-201908104 | |
VMware ESXi | =6.7-670-201908201 | |
VMware ESXi | =6.7-670-201908202 | |
VMware ESXi | =6.7-670-201908203 | |
VMware ESXi | =6.7-670-201908204 | |
VMware ESXi | =6.7-670-201908205 | |
VMware ESXi | =6.7-670-201908206 | |
VMware ESXi | =6.7-670-201908207 | |
VMware ESXi | =6.7-670-201908208 | |
VMware ESXi | =6.7-670-201908209 | |
VMware ESXi | =6.7-670-201908210 | |
VMware ESXi | =6.7-670-201908211 | |
VMware ESXi | =6.7-670-201908212 | |
VMware ESXi | =6.7-670-201908213 | |
VMware ESXi | =6.7-670-201908214 | |
VMware ESXi | =6.7-670-201908215 | |
VMware ESXi | =6.7-670-201908216 | |
VMware ESXi | =6.7-670-201908217 | |
VMware ESXi | =6.7-670-201908218 | |
VMware ESXi | =6.7-670-201908219 | |
VMware ESXi | =6.7-670-201908220 | |
VMware ESXi | =6.7-670-201908221 | |
VMware ESXi | =6.7-670-201911001 | |
VMware ESXi | =6.7-670-201912001 | |
VMware ESXi | =6.7-670-201912101 | |
VMware ESXi | =6.7-670-201912102 | |
VMware ESXi | =6.7-670-201912401 | |
VMware ESXi | =6.7-670-201912402 | |
VMware ESXi | =6.7-670-201912403 | |
VMware ESXi | =6.7-670-201912404 | |
VMware ESXi | =6.7-670-201912405 | |
VMware ESXi | =6.7-670-202004001 | |
VMware ESXi | =6.7-670-202004002 | |
VMware ESXi | =6.7-670-202004301 | |
VMware ESXi | =6.7-670-202004401 | |
VMware ESXi | =6.7-670-202004402 | |
VMware ESXi | =6.7-670-202004403 | |
VMware ESXi | =6.7-670-202004404 | |
VMware ESXi | =6.7-670-202004405 | |
VMware ESXi | =6.7-670-202004406 | |
VMware ESXi | =6.7-670-202004407 | |
VMware ESXi | =6.7-670-202004408 | |
VMware ESXi | =6.7-670-202006001 | |
VMware ESXi | =6.7-670-202008001 | |
VMware ESXi | =6.7-670-202010001 | |
VMware ESXi | =6.7-670-202011001 | |
VMware ESXi | =6.7-670-202011002 | |
VMware ESXi | =6.7-670-202102001 | |
VMware ESXi | =6.7-670-202103001 | |
VMware ESXi | =7.0 | |
VMware ESXi | =7.0-beta | |
VMware ESXi | =7.0-update_1 | |
VMware ESXi | =7.0-update_1a | |
VMware ESXi | =7.0-update_1b | |
VMware ESXi | =7.0-update_1c | |
VMware ESXi | =7.0-update_1d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21994 has been rated as critical due to its potential to allow unauthorized access to sensitive data.
To mitigate CVE-2021-21994, upgrade to the latest version of ESXi or VMware Cloud Foundation as specified in the security advisory.
CVE-2021-21994 is an authentication bypass vulnerability in SFCB used in ESXi that allows malicious actors to exploit unauthorized access.
CVE-2021-21994 affects VMware ESXi versions 6.5 and 6.7, as well as specific versions of VMware Cloud Foundation.
Yes, an attacker with network access to port 5989 on ESXi can exploit CVE-2021-21994 remotely.