CVE-2021-22011: Medium severity vmware vcenter server and cloud foundation vulnerability
Published Sep 23, 2021
·Updated
vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.
Affected Software
4 affected components
VMware Cloud Foundation>=3.0<5.0
VMware vCenter Server=6.5
VMware vCenter Server=6.7
VMware vCenter Server=7.0
Remediation
Event History
Sep 23, 2021
CVE Published
via MITRE·11:51 AM
Data Sourced
via MITRE·11:51 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-22011.
2
What is the title of this vulnerability?
The title of this vulnerability is 'vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library.'
3
What is the severity of CVE-2021-22011?
The severity of CVE-2021-22011 is medium.
4
Which versions of VMware Cloud Foundation are affected by this vulnerability?
Versions 3.0 to 5.0 of VMware Cloud Foundation are affected by this vulnerability.
5
How can a malicious actor exploit this vulnerability?
A malicious actor with network access to port 443 on vCenter Server can exploit this vulnerability to perform unauthenticated VM network setting manipulation.