CVE-2021-21978 is a critical remote code execution (RCE) vulnerability affecting VMware View Planner 4.x prior to 4.6 Security Patch 1. This flaw stems from improper input validation and a lack of authorization in the logupload web application, allowing an unauthenticated attacker with network access to upload and execute malicious files. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, enabling full compromise of the affected system. Exploit code is publicly available via Metasploit and Nuclei templates, and it has garnered significant community discussion and media coverage, though it is not currently listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0, < 4.6CPE matchmatch criteria | cpe:2.3:a:vmware:view_planner:*:*:*:*:*:*:*:* | ||
4.6CPE matchmatch criteria | cpe:2.3:a:vmware:view_planner:4.6:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.