CVE-2021-22014: Critical severity vmware vcenter server and cloud foundation vulnerability
The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22014?
CVE-2021-22014 is an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure) in vCenter Server.
How does CVE-2021-22014 affect VMware Cloud Foundation?
CVE-2021-22014 affects VMware Cloud Foundation versions 3.0 to 5.0, allowing an authenticated VAMI user with network access to execute code on the underlying operating system.
How does CVE-2021-22014 affect VMware vCenter Server 6.5?
CVE-2021-22014 affects VMware vCenter Server version 6.5, allowing an authenticated VAMI user with network access to execute code on the underlying operating system.
How does CVE-2021-22014 affect VMware vCenter Server 6.7?
CVE-2021-22014 affects VMware vCenter Server version 6.7, allowing an authenticated VAMI user with network access to execute code on the underlying operating system.
How does CVE-2021-22014 affect VMware vCenter Server 7.0?
CVE-2021-22014 affects VMware vCenter Server version 7.0, allowing an authenticated VAMI user with network access to execute code on the underlying operating system.
What is the severity of CVE-2021-22014?
CVE-2021-22014 has a severity rating of 7.2 (critical).
How can I fix CVE-2021-22014?
To fix CVE-2021-22014, apply the necessary security patches or updates provided by VMware.