ZeroHour

CVE-2021-22003

CVSS 3.1
7.5 high
EPSS
<1%p61
Published
()
Modified
Description

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

Vendors
vmware
Products
identity manager, workspace one access, cloud foundation, vrealize suite lifecycle manager
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news