« Volver al listado

CVE-2021-21972

Estado: AnalizadaCrítica (9.8)⚠ Explotación activa

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

RCE en vCenter Server accesible por red (AV:N, PR:N) sin interacción: T1190. Ejecución de comandos con privilegios sin restricción confirmada. Acceso a datos del servidor virtualizado probable.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-21972",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2021-21972",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2021-02-23T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "VMware vCenter Server",
          "versions": [
            {
              "status": "affected",
              "version": "7.x before 7.0 U1c"
            },
            {
              "status": "affected",
              "version": "6.7 before 6.7 U3l"
            },
            {
              "status": "affected",
              "version": "6.5 before 6.5 U3n"
            }
          ]
        },
        {
          "vendor": "n/a",
          "product": "VMware Cloud Foundation",
          "versions": [
            {
              "status": "affected",
              "version": "4.x before 4.2"
            },
            {
              "status": "affected",
              "version": "3.x before 3.10.1.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-02-24T17:15:15.833",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2021-0002.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "http://packetstormsecurity.com/files/161590/VMware-vCenter-Server-7.0-Arbitrary-File-Upload.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/161695/VMware-vCenter-Server-File-Upload-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/163268/VMware-vCenter-6.5-6.7-7.0-Remote-Code-Execution.html",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2021-0002.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21972",
      "tags": [
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2)."
    },
    {
      "lang": "es",
      "value": "El VSphere Client (HTML5) contiene una vulnerabilidad de ejecución de código remota en un plugin de vCenter Server. Un actor malicioso con acceso de red al puerto 443 puede explotar este problema para ejecutar comandos con privilegios no restringidos en el sistema operativo subyacente que aloja vCenter Server. Esto afecta a VMware vCenter Server (versiones 7.x anteriores a 7.0 U1c, versiones 6.7 anteriores a 6.7 U3l y versiones 6.5 anteriores a 6.5 U3n) y VMware Cloud Foundation (versiones 4.x anteriores a 4.2 y versiones 3.x anteriores a 3.10.1.2)"
    }
  ],
  "lastModified": "2026-08-12T05:17:35.260",
  "cisaActionDue": "2021-11-17",
  "cisaExploitAdd": "2021-11-03",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1995769A-1AB9-47FA-966A-8E82D414161E",
              "versionEndExcluding": "3.10.1.2",
              "versionStartIncluding": "3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A608D809-6E65-4228-9207-CB470529C542",
              "versionEndExcluding": "4.2",
              "versionStartIncluding": "4.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23CFE5A5-A166-4FD5-BE97-5F16DAB1EAE0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CF7DDB0C-3C07-4B5E-8B8A-0542FEE72877"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DD16169-A7DF-4604-888C-156A60018E32"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46FC9F34-C8FA-4AFE-9F4A-7CF9516BD4D9"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D26534EB-327B-4ED6-A3E1-005552CB1F9D"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:e:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "786CDD50-7E18-4437-8DB9-2D0ADECD436E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:f:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2CE8DAE-0E78-4004-983D-1ECD8855EC33"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F72A1E9C-F960-4E8C-A46C-B38209E6349E"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C33CE46-F529-4EA9-9344-6ED3BFA7019D"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F1D8161-0E02-45C9-BF61-14799AB65E03"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F2CB1FF-6118-4875-945D-07BAA3A21FFA"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AEDA28A-5C8E-4E95-A377-3BE530DBEAB5"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDDC6510-3116-4578-80C8-8EF044A8370A"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8678DB48-CB98-4E4C-ADE6-CABA73265FEC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DBD9A341-1FBF-4E04-848B-550DEB27261A"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4955663C-1BB6-4F3E-9D4B-362DF144B7F1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE0F8453-3D6C-4F1C-9167-3F02E3D905DC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EAD4045-A7F9-464F-ABB9-3782941162CC"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.5:update3k:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F0A79C2-33AE-40C5-A853-770A4C691F29"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E456F84C-A86E-4EA9-9A3E-BEEA662136E6"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5241C282-A02B-44B2-B6CA-BA3A99F9737C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04A60AC7-C2EA-4DBF-9743-54D708584AFA"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A91B0C4-F184-459E-AFD3-DE0E351CC964"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23253631-2655-48A8-9B00-CB984232329C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50C2A9A8-0E66-4702-BCD4-74622108E7A6"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE4D3E2A-C32D-408F-B811-EF8BC86F0D34"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31CA7802-D78D-4BAD-A45A-68B601C010C6"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B98981B-4721-4752-BAB4-361DB5AEB86F"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04487105-980A-4943-9360-4442BF0411E6"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update3a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24D24E06-EB3F-4F11-849B-E66757B01466"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update3b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8AF12716-88E2-44B5-ACD7-BCBECA130FB8"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update3f:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3352212C-E820-47B3-BDF5-57018F5B9E81"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update3g:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6436ADFD-6B94-4D2A-B09B-CED4EC6CA276"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:6.7:update3j:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D06832CE-F946-469D-B495-6735F18D02A0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5FA81CCD-A05E-498C-820E-21980E92132F"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EE83406-A3D9-4F75-A1A6-63831CEBEEC1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB563627-C9CF-4D8A-B882-9AB65EAE9E15"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCA03B2A-48B2-48AD-B8EB-9D7BB2016819"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2392D0F-D7A2-4E01-9212-1BA6C895AEBF"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D731C1A-9FE5-461C-97E2-6F45E4CBABE1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8725E544-2A94-4829-A683-1ECCE57A74A6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com",
  "cisaRequiredAction": "Apply updates per vendor instructions.",
  "cisaVulnerabilityName": "VMware vCenter Server Remote Code Execution Vulnerability"
}