ZeroHour

CVE-2021-21973

KEVlarge

SSRF in VMware vCenter Server and Cloud Foundation (vSphere Client HTML5)

CISA: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

CVSS 3.1
5.3 medium
EPSS
88%p100
Published
()
KEV added
AI analysis

CVE-2021-21973 is a server-side request forgery (SSRF, CWE-918) in the vSphere Client (HTML5), caused by improper validation of URLs in a vCenter Server plugin. An unauthenticated attacker with network access to TCP port 443 can trigger it by sending a crafted POST request to the affected vCenter Server plugin, causing vCenter to make attacker-influenced internal requests. The direct impact is information disclosure (confidentiality only, CVSS 3.1 base 5.3), but SSRF in vCenter is frequently chained with other vCenter flaws to reach remote code execution, as reflected in the related advisories. Everyone running VMware vCenter Server 7.x/6.7/6.5 or VMware Cloud Foundation 4.x/3.x before the fixed releases is affected. The flaw is actively exploited: it is listed in CISA KEV (added 2022-03-07) and carries a very high EPSS (87.6%), with reporting of coordinated SSRF exploitation campaigns involving hundreds of source IPs.

What to do: Upgrade vCenter Server to 7.0 U1c, 6.7 U3l, or 6.5 U3n, and Cloud Foundation to 4.2 or 3.10.1.2, per VMware's instructions. Until patched, restrict access to vCenter's port 443 from untrusted networks and review access logs for suspicious unauthenticated POST requests to the vSphere Client plugin endpoints. Given the KEV listing and reports of coordinated SSRF exploitation, treat patching as urgent even though this flaw alone yields information disclosure.

Affected
vmware vCenter Server7.x before 7.0 U1c
vmware vCenter Server6.7 before 6.7 U3l
vmware vCenter Server6.5 before 6.5 U3n
vmware Cloud Foundation4.x before 4.2
vmware Cloud Foundation3.x before 3.10.1.2
Estimated exposure
largetens of thousands of internet-exposed vCenter instances (likely 50,000+ on public port 443), with far more deployed internally in enterprise data centers — vCenter is the standard management appliance for VMware's dominant enterprise virtualization stack, and public internet-wide scans have repeatedly shown tens of thousands of vCenter servers reachable on port 443, so the plausibly affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

CISA Known Exploited Vulnerability
Affected
VMware vCenter Server and Cloud Foundation
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
cloud foundation, vcenter server
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news