CVE-2021-22014 is an authenticated code execution vulnerability found in the Virtual Appliance Management Infrastructure (VAMI) of VMware vCenter Server and Cloud Foundation. An authenticated user with network access to port 5480 can exploit this to execute arbitrary code on the underlying operating system, leading to high impact on confidentiality, integrity, and availability. Rated 7.2 HIGH on CVSS, this vulnerability requires high privileges but has low attack complexity. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it shows no signs of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 5.0CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
6.5CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.