CVE-2021-21998: Critical severity vmware carbon black vulnerability
VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21998?
CVE-2021-21998 has a high severity rating due to the potential for unauthorized administrative access.
How do I fix CVE-2021-21998?
To remediate CVE-2021-21998, upgrade VMware Carbon Black App Control to version 8.5.8 or later, or 8.6.2 or later.
Who is affected by CVE-2021-21998?
CVE-2021-21998 affects VMware Carbon Black App Control versions 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2.
What type of vulnerability is CVE-2021-21998?
CVE-2021-21998 is classified as an authentication bypass vulnerability.
Can CVE-2021-21998 be exploited remotely?
Yes, CVE-2021-21998 can be exploited remotely by malicious actors with network access to the VMware Carbon Black App Control management server.