CVE-2021-21985 is a critical remote code execution vulnerability in the vSphere Client (HTML5) Virtual SAN Health Check plug-in, affecting VMware vCenter Server and Cloud Foundation. This flaw allows an unauthenticated attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system. With a CVSS score of 9.8 and an EPSS score indicating high exploitability, it poses a severe risk, enabling full compromise of the host system. The vulnerability is actively exploited, including in ransomware campaigns, with public Metasploit modules and Nuclei templates available, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.