CVE-2021-21995 is a denial-of-service vulnerability in OpenSLP, affecting VMware ESXi and Cloud Foundation, caused by a heap out-of-bounds read. An unauthenticated attacker with network access to port 427 can trigger this flaw, leading to a denial-of-service condition. With a CVSS score of 7.5 (High), it requires no user interaction and has low attack complexity. While not listed in CISA's KEV catalog, there is significant community discussion and media coverage, including reports linking it to ransomware attacks, despite no public exploit code being readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 3.10.2CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
>= 4.0, < 4.3CPE matchmatch criteria | cpe:2.3:o:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:o:vmware:esxi:6.5:650-201703001:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.