Vcenter Server
Vendor:
First CVE: Mar 25, 2009 · Active for 17 years
79
Total CVEs
More Total CVEs than 99% of tracked products
6.1
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
13.9%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Vcenter Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2009
17 years ago
Most Recent CVE
Sep 17, 2024
675 days ago
CVE Severity & Scoring
Vcenter Server79 CVEs
38%
38%
23%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (10.1%)
Network61 (77.2%)
Unknown10 (12.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low65 (82.3%)
High4 (5.1%)
Unknown10 (12.7%)
User Interaction
None61 (77.2%)
Unknown10 (12.7%)
Required8 (10.1%)
Privileges Required
Low19 (24.1%)
High4 (5.1%)
None46 (58.2%)
Unknown10 (12.7%)
Top CVEs
Signals from CVEs in this product scope (79 CVEs).
79 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21972CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to ex | Feb 24, 2021 | 9.8 | 99 | YES | YES |
CVE-2023-34048CRITICAL vCenter Server contains an out-of-bounds write vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an ou | Oct 25, 2023 | 9.8 | 98 | YES | YES |
CVE-2021-22005CRITICAL The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this is | Sep 23, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-21985CRITICAL The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCe | May 26, 2021 | 9.8 | 98 | YES | YES |
CVE-2020-3952CRITICAL Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Services Controller (PSC), does not correctly implement access co | Apr 10, 2020 | 9.8 | 98 | YES | YES |
CVE-2021-21973MEDIUM The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with networ | Feb 24, 2021 | 5.3 | 94 | YES | YES |
CVE-2024-38812CRITICAL The vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vul | Sep 17, 2024 | 9.8 | 90 | YES | NO |
CVE-2021-22017MEDIUM Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Serve | Sep 23, 2021 | 5.3 | 87 | YES | YES |
CVE-2015-2342HIGH The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attacker | Oct 12, 2015 | 10.0 | 87 | NO | YES |
CVE-2024-37079CRITICAL vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnera | Jun 18, 2024 | 9.8 | 80 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (79 CVEs).
CISA KEV
11 CVEs
13.9% of CVEs· 98th percentile
Metasploit
8 CVEs
10.1% of CVEs· 97th percentile
Nuclei
7 CVEs
8.9% of CVEs· 97th percentile
ExploitDB
4 CVEs
5.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (79 CVEs).
Media Mentions
Signals from CVEs in this product scope (79 CVEs).
Top CNAs Publishing CVEs For Vcenter Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0 | 15 | 8.3 | 16.8% | 4 | 2 |
| 7.0 | 43 | 8.1 | 19.1% | 9 | 8 |
| 6.7 | 37 | 7.0 | 22.3% | 7 | 8 |
| 6.5 | 34 | 7.2 | 21.2% | 5 | 6 |
| 6.0 | 9 | 7.1 | 2.6% | 0 | 1 |
| 5.5 | 10 | 7.0 | 3.6% | 0 | 1 |
| 5.1 | 5 | 6.3 | 19.6% | 0 | 1 |
| 5.0 | 9 | 7.1 | 8.1% | 0 | 1 |
| 4.1.0.17435 | 1 | 6.8 | 2.0% | 0 | 0 |
| 4.1.0.14766 | 1 | 6.8 | 2.0% | 0 | 0 |
| 4.1.0.12319 | 1 | 6.8 | 2.0% | 0 | 0 |
| 4.1 | 4 | 7.0 | 1.5% | 0 | 0 |
| 4.0.0.12305 | 1 | 6.8 | 2.0% | 0 | 0 |
| 4.0.0.10021 | 1 | 6.8 | 2.0% | 0 | 0 |
| 4.0 | 5 | 7.5 | 2.3% | 0 | 1 |