CVE-2021-22013 is a file path traversal vulnerability in the vCenter Server appliance management API, affecting VMware Cloud Foundation and vCenter Server. This high-severity vulnerability (CVSS 7.5) allows an unauthenticated attacker with network access to port 443 to disclose sensitive information. While no public exploit code (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV) has been observed, and community discussion is minimal, organizations should still patch promptly to mitigate the risk of information exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 5.0CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.