ZeroHour

CVE-2021-22017

KEVlarge

Improper access control via URI normalization in VMware vCenter rhttproxy

CISA: VMware vCenter Server Improper Access Control

CVSS 3.1
5.3 medium
EPSS
49%p99
Published
()
KEV added
AI analysis

CVE-2021-22017 is an improper access control flaw (CWE-23, relative path traversal) in rhttproxy, the reverse HTTP proxy that fronts VMware vCenter Server, caused by improper URI normalization of incoming HTTP/HTTPS requests. An attacker with network access to the vCenter interface (typically TCP 443) can send crafted URLs whose traversal/normalization quirks cause rhttproxy to route requests past its access controls to internal vCenter endpoints. The attacker's gain is unauthorized access — effectively bypassing the proxy/lookup-service boundary — which also makes the bug useful as a foothold or component in chained attacks toward broader vCenter compromise. Any organization running an affected vCenter Server version is exposed, particularly where the management interface is internet-reachable; the CISA record does not enumerate version ranges, so admins should consult VMware advisory VMSA-2021-0020 for the affected and fixed builds. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-01-10 (ransomware association unknown), though no public PoC has been published.

What to do: Upgrade vCenter Server to the fixed build for your branch listed in VMware advisory VMSA-2021-0020 (6.5/6.7/7.0 families); the KEV listing makes patching mandatory for CISA-required remediation timelines. Restrict exposure of vCenter's 443 interface to trusted networks (VPN/firewall) and review rhttproxy/proxy logs for anomalous or traversal-style URLs. Ransomware linkage is unconfirmed, but treat any unpatched, internet-facing vCenter as high risk.

Affected
VMware vCenter Server (rhttproxy component)Version ranges not specified in the CISA record (CISA lists only 'VMware vCenter Server'); per VMware advisory VMSA-2021-0020 the 6.5, 6.7 and 7.0 branches were
Estimated exposure
largetens of thousands of internet-exposed vCenter instances (≈10k–100k systems), with a total installed base plausibly in the hundreds of thousands — vCenter is the de facto management plane for nearly every VMware vSphere deployment, and public internet-wide scans (Shodan/Censys) have repeatedly found on the order of tens of thousands of exposed vCenter login endpoints on TCP 443.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

CISA Known Exploited Vulnerability
Affected
VMware vCenter Server
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
vcenter server
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news