ZeroHour

CVE-2021-22011

CVSS 3.1
5.3 medium
EPSS
1%p63
Published
()
Modified
Description

vCenter Server contains an unauthenticated API endpoint vulnerability in vCenter Server Content Library. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to perform unauthenticated VM network setting manipulation.

Vendors
vmware
Products
cloud foundation, vcenter server
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news