CVE-2021-21975 is a critical Server-Side Request Forgery (SSRF) vulnerability in VMware vRealize Operations Manager API, affecting versions prior to 8.4, as well as Cloud Foundation and vRealize Suite Lifecycle Manager. With a CVSS score of 7.5 (HIGH), this vulnerability allows unauthenticated attackers with network access to steal administrative credentials. It is actively exploited in the wild, including in ransomware campaigns, and has readily available exploit code via Metasploit and Nuclei templates. The high EPSS score, FAUCET Risk Score of 100/100, and extensive community discussion underscore its severe and immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.0:*:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.0.1:*:*:*:*:*:*:* | ||
3.0.1.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.0.1.1:*:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.5:*:*:*:*:*:*:* | ||
3.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.