CVE-2021-21973
KEVlargeSSRF in VMware vCenter Server and Cloud Foundation (vSphere Client HTML5)
CISA: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
CVE-2021-21973 is a server-side request forgery (SSRF, CWE-918) in the vSphere Client (HTML5), caused by improper validation of URLs in a vCenter Server plugin. An unauthenticated attacker with network access to TCP port 443 can trigger it by sending a crafted POST request to the affected vCenter Server plugin, causing vCenter to make attacker-influenced internal requests. The direct impact is information disclosure (confidentiality only, CVSS 3.1 base 5.3), but SSRF in vCenter is frequently chained with other vCenter flaws to reach remote code execution, as reflected in the related advisories. Everyone running VMware vCenter Server 7.x/6.7/6.5 or VMware Cloud Foundation 4.x/3.x before the fixed releases is affected. The flaw is actively exploited: it is listed in CISA KEV (added 2022-03-07) and carries a very high EPSS (87.6%), with reporting of coordinated SSRF exploitation campaigns involving hundreds of source IPs.
What to do: Upgrade vCenter Server to 7.0 U1c, 6.7 U3l, or 6.5 U3n, and Cloud Foundation to 4.2 or 3.10.1.2, per VMware's instructions. Until patched, restrict access to vCenter's port 443 from untrusted networks and review access logs for suspicious unauthenticated POST requests to the vSphere Client plugin endpoints. Given the KEV listing and reports of coordinated SSRF exploitation, treat patching as urgent even though this flaw alone yields information disclosure.
| vmware vCenter Server | 7.x before 7.0 U1c |
| vmware vCenter Server | 6.7 before 6.7 U3l |
| vmware vCenter Server | 6.5 before 6.5 U3n |
| vmware Cloud Foundation | 4.x before 4.2 |
| vmware Cloud Foundation | 3.x before 3.10.1.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
- Affected
- VMware vCenter Server and Cloud Foundation
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- cloud foundation, vcenter server
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N