Critical Auth Bypass Bug Found in VMware Data Center Security Product
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-21975 | SSRF in VMware vRealize Operations Manager API Enables Admin Credential Theft CVE-2021-21975 is a server-side request forgery (CWE-918) in the vRealize Operations Manager API affecting versions prior to 8.4. A malicious actor with network access to the vRealize Operations Manager API endpoint can trigger the flaw without authentication or user interaction, causing the server to make attacker-influenced requests. Successful abuse lets the attacker steal administrative credentials for vRealize Operations Manager; a public proof-of-concept additionally demonstrates chaining the SSRF into code execution. Organizations running vRealize Operations Manager on-premises, including VMware Cloud Foundation and vRealize Suite Lifecycle Manager deployments that include it, are affected. The flaw is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-01-18) with known ransomware use and carries a very high EPSS score of 78.3%, indicating active, widespread exploitation. Do: Upgrade vRealize Operations Manager to version 8.4 or later (or apply the update in the bundled Cloud Foundation / vRealize Suite Lifecycle Manager releases per VMware's advisory instructions), as required by CISA's KEV listing. Restrict network access to the vRealize Operations Manager API to trusted management networks until patched, and review logs for signs of SSRF-driven requests or unauthorized use of stolen administrative credentials, given the known ransomware exploitation. | 7.5 | 78% | KEV ransomware PoC |
| largetens of thousands of enterprise deployments (thousands of instances exposed to the internet) | |
| CVE-2021-21982 | VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to t VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings. NVD description · AI analysis pending | 9.1 | 1% |
| — | ||
| CVE-2021-21983 | Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network acce Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system. NVD description · AI analysis pending | 6.5 | 69% | PoC |
| — |
Full article378 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 07, 2021
A critical vulnerability in the VMware Carbon Black Cloud Workload appliance could be exploited to bypass authentication and take control of vulnerable systems.
Tracked as CVE-2021-21982, the flaw is rated 9.1 out of a maximum of 10 in the CVSS scoring system and affects all versions of the product prior to 1.0.1.
Carbon Black Cloud Workload is a data center security product from VMware that aims to protect critical servers and workloads hosted on vSphere, the company's cloud-computing virtualization platform.
"A URL on the administrative interface of the VMware Carbon Black Cloud Workload appliance can be manipulated to bypass authentication," VMware said in its advisory, thereby allowing an adversary with network access to the interface to gain access to the administration API of the appliance.
Armed with the access, a malicious actor can then view and alter administrative configuration settings, the company added.
In addition to releasing a fix for CVE-2021-21982, VMware has also addressed two separate bugs in its vRealize Operations Manager solution that an attacker with network access to the API could exploit to carry out Server Side Request Forgery (SSRF) attacks to steal administrative credentials (CVE-2021-21975) and write files to arbitrary locations on the underlying photon operating system (CVE-2021-21983).
The product is primarily designed to monitor and optimize the performance of the virtual infrastructure and support features such as workload balancing, troubleshooting, and compliance management.
Egor Dimitrenko, a security researcher with Positive Technologies, has been credited with reporting all three flaws.
"The main risk is that administrator privileges allow attackers to exploit the second vulnerability—CVE-2021-21983 (an arbitrary file write flaw, scored 7.2), which allows executing any commands on the server," Dimitrenko said. "The combination of two security flaws makes the situation even more dangerous, as it allows an unauthorized attacker to obtain control over the server and move laterally within the infrastructure."
VMware has released patches for vRealize Operations Manager versions 7.0.0, 7.5.0, 8.0.1, 8.1.1, 8.2.0 and 8.3.0. The company has also published workarounds to mitigate the risks associated with the flaws in scenarios where the patch cannot be installed or is not available.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/04/critical-auth-bypass-bug-found-in.html