CVE-2021-21983 is an arbitrary file write vulnerability in the vRealize Operations Manager API, affecting versions prior to 8.4 of vRealize Operations Manager, Cloud Foundation, and vRealize Suite Lifecycle Manager. An authenticated attacker with network access can write files to arbitrary locations on the underlying Photon OS. With a CVSS score of 6.5 (Medium), this vulnerability has high impact on integrity and availability, requiring high privileges but no user interaction. While not on the KEV catalog, a Metasploit module exists, and its high EPSS score and community discussion indicate significant exploitability potential, with media coverage highlighting its serious implications for organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.0:*:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.0.1:*:*:*:*:*:*:* | ||
3.0.1.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.0.1.1:*:*:*:*:*:*:* | ||
3.5CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.5:*:*:*:*:*:*:* | ||
3.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:3.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.