CVE-2021-22017 is a medium-severity vulnerability in VMware vCenter Server's Rhttproxy, stemming from improper URI normalization. This flaw allows an unauthenticated attacker with network access to port 443 to bypass proxy controls and access internal endpoints. With a CVSS score of 5.3, it presents a low attack complexity and no user interaction, potentially leading to information disclosure. This vulnerability is actively exploited in the wild, listed in CISA's KEV catalog, and has garnered significant community discussion and media coverage, despite a lack of public Metasploit or ExploitDB modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.7CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.