CVE-2021-22017
KEVlargeImproper access control via URI normalization in VMware vCenter rhttproxy
CISA: VMware vCenter Server Improper Access Control
CVE-2021-22017 is an improper access control flaw (CWE-23, relative path traversal) in rhttproxy, the reverse HTTP proxy that fronts VMware vCenter Server, caused by improper URI normalization of incoming HTTP/HTTPS requests. An attacker with network access to the vCenter interface (typically TCP 443) can send crafted URLs whose traversal/normalization quirks cause rhttproxy to route requests past its access controls to internal vCenter endpoints. The attacker's gain is unauthorized access — effectively bypassing the proxy/lookup-service boundary — which also makes the bug useful as a foothold or component in chained attacks toward broader vCenter compromise. Any organization running an affected vCenter Server version is exposed, particularly where the management interface is internet-reachable; the CISA record does not enumerate version ranges, so admins should consult VMware advisory VMSA-2021-0020 for the affected and fixed builds. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-01-10 (ransomware association unknown), though no public PoC has been published.
What to do: Upgrade vCenter Server to the fixed build for your branch listed in VMware advisory VMSA-2021-0020 (6.5/6.7/7.0 families); the KEV listing makes patching mandatory for CISA-required remediation timelines. Restrict exposure of vCenter's 443 interface to trusted networks (VPN/firewall) and review rhttproxy/proxy logs for anomalous or traversal-style URLs. Ransomware linkage is unconfirmed, but treat any unpatched, internet-facing vCenter as high risk.
| VMware vCenter Server (rhttproxy component) | Version ranges not specified in the CISA record (CISA lists only 'VMware vCenter Server'); per VMware advisory VMSA-2021-0020 the 6.5, 6.7 and 7.0 branches were |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
- Affected
- VMware vCenter Server
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- vcenter server
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N