ZeroHour

CVE-2021-21975

KEV ransomware PoC large

SSRF in VMware vRealize Operations Manager API Enables Admin Credential Theft

CISA: VMware Server Side Request Forgery in vRealize Operations Manager API

CVSS 3.1
7.5 high
EPSS
78%p100
Published
()
KEV added
AI analysis

CVE-2021-21975 is a server-side request forgery (CWE-918) in the vRealize Operations Manager API affecting versions prior to 8.4. A malicious actor with network access to the vRealize Operations Manager API endpoint can trigger the flaw without authentication or user interaction, causing the server to make attacker-influenced requests. Successful abuse lets the attacker steal administrative credentials for vRealize Operations Manager; a public proof-of-concept additionally demonstrates chaining the SSRF into code execution. Organizations running vRealize Operations Manager on-premises, including VMware Cloud Foundation and vRealize Suite Lifecycle Manager deployments that include it, are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-01-18) with known ransomware use and carries a very high EPSS score of 78.3%, indicating active, widespread exploitation.

What to do: Upgrade vRealize Operations Manager to version 8.4 or later (or apply the update in the bundled Cloud Foundation / vRealize Suite Lifecycle Manager releases per VMware's advisory instructions), as required by CISA's KEV listing. Restrict network access to the vRealize Operations Manager API to trusted management networks until patched, and review logs for signs of SSRF-driven requests or unauthorized use of stolen administrative credentials, given the known ransomware exploitation.

Affected
vmware vrealize operations managerprior to 8.4
vmware cloud foundationdeployments bundling vRealize Operations Manager prior to 8.4
vmware vrealize suite lifecycle managerdeployments bundling vRealize Operations Manager prior to 8.4
Estimated exposure
largetens of thousands of enterprise deployments (thousands of instances exposed to the internet) — vRealize Operations Manager is widely deployed by enterprises managing VMware virtualization estates, and public internet scans around the disclosure period found thousands of exposed vROps API instances, supporting an order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.

CISA Known Exploited Vulnerability
Affected
VMware vRealize Operations Manager API
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
vmware
Products
cloud foundation, vrealize operations manager, vrealize suite lifecycle manager
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news