CVE-2021-21986 is a critical authentication bypass vulnerability in the vSphere Client (HTML5) affecting VMware vCenter Server and Cloud Foundation. An unauthenticated attacker with network access to port 443 can exploit this flaw to perform actions allowed by several vSphere plug-ins, including vSAN Health Check and Site Recovery. With a CVSS score of 9.8, this vulnerability poses a high risk of complete compromise (confidentiality, integrity, availability) due to its network-based attack vector and low attack complexity. While not currently listed on the KEV catalog, the vulnerability has garnered significant community attention and media coverage, with VMware urging immediate patching, though no public exploit code is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.