CVE-2021-21975
published 2021-03-31CVE-2021-21975: Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize…
PriorityP193high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-02-01
Exploited in the wild
EPSS
78.29%
99.5th percentile
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_operations_manager | — | — |
| vmware | vrealize_suite_lifecycle_manager | — | — |
| vmware | vrealize_suite_lifecycle_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
commandPOST /casa/nodes/thumbprints HTTP/1.1
Host: {{Hostname}}
Content-Type: application/json;charset=UTF-8
["127.0.0.1:443/ui/"]↗
- →Detect SSRF exploitation attempts by monitoring POST requests to /casa/nodes/thumbprints with a JSON body containing internal/loopback IP addresses (e.g., 127.0.0.1). ↗
- →Successful SSRF exploitation response body will contain the strings 'vRealize Operations Manager', 'thumbprint', and 'address' with HTTP 200 status — use these as detection signatures. ↗
- →Monitor for unauthenticated POST requests to /casa/nodes/thumbprints followed by authenticated POST requests to /casa/private/config/slice/ha/certificate, which indicates chained CVE-2021-21975 + CVE-2021-21983 exploitation leading to RCE. ↗
- →Code execution from the chained exploit occurs as the 'admin' Unix user — alert on unexpected process spawning or file writes by the 'admin' user on vROps hosts. ↗
- ·Version 8.3.0 is vulnerable to the SSRF (CVE-2021-21975) but credential theft is not exploitable, so the Metasploit chained RCE module does not support it. ↗
- ·A temporary workaround (not a fix) involves modifying the casa-security-context.xml file and restarting the Cluster Analytic (CaSA) service; this must be replaced by patching. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
cisa7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-px27-325w-m34c: Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8
ghsa_unreviewed·2022-05-24·CVSS 7.5
CVE-2021-21975 [HIGH] CWE-918 GHSA-px27-325w-m34c: Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credentials.
VulnCheck
VMware Server Side Request Forgery in vRealize Operations Manager API
vulncheck·2021·CVSS 7.5
CVE-2021-21975 [HIGH] CWE-918 VMware Server Side Request Forgery in vRealize Operations Manager API
VMware Server Side Request Forgery in vRealize Operations Manager API
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
Affected: VMware vRealize Operations Manager API
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://unit42.paloaltonetworks.com/network-attack-trends-february-april-2021/; https://vblocalhost.com/uploads/VB2021-50.pdf; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2023-11-17&host_type=src&vulnerabili
CISA
VMware Server Side Request Forgery in vRealize Operations Manager API
cisa·2022-01-18·CVSS 7.5
CVE-2021-21975 [HIGH] CWE-918 VMware Server Side Request Forgery in vRealize Operations Manager API
Vulnerability: VMware Server Side Request Forgery in vRealize Operations Manager API
Affected: VMware vRealize Operations Manager API
Server Side Request Forgery (SSRF) in vRealize Operations Manager API prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API to perform a SSRF attack to steal administrative credentials.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-21975
Remediation Due Date: 2022-02-01
VMware
VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)
vendor_vmware·2021-03-30·CVSS 7.5
CVE-2021-21975 [HIGH] VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)
VMSA-2021-0004: VMware vRealize Operations updates address Server Side Request Forgery and Arbitrary File Write vulnerabilities (CVE-2021-21975, CVE-2021-21983)
The vRealize Operations Manager API contains a Server Side Request Forgery. VMware has evaluated this issue to be of 'Important' severity with a maximum CVSSv3 base score of 8.6.
CVEs: CVE-2021-21975, CVE-2021-21983
Affected products: VMware Aria, VMware Cloud Foundation, VMware vRealize
Suricata
ET EXPLOIT Possible vRealize Operations Manager API SSRF Attempt (CVE-2021-21975)
suricata·2022-01-25·CVSS 7.5
CVE-2021-21975 [HIGH] ET EXPLOIT Possible vRealize Operations Manager API SSRF Attempt (CVE-2021-21975)
ET EXPLOIT Possible vRealize Operations Manager API SSRF Attempt (CVE-2021-21975)
Rule: alert http1 any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible vRealize Operations Manager API SSRF Attempt (CVE-2021-21975)"; flow:established,to_server; http.request_line; content:"POST /casa/nodes/thumbprints HTTP/1.1"; fast_pattern; http.request_body; content:"|5b|"; http.content_type; bsize:30; content:"application/json|3b|charset=UTF-8"; reference:cve,2021-21975; classtype:attempted-admin; sid:2034974; rev:4; metadata:attack_target Server, created_at 2022_01_25, cve CVE_2021_21975, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_04;)
Metasploit
VMware vRealize Operations (vROps) Manager SSRF RCE
metasploit·CVSS 7.5
CVE-2021-21975 [HIGH] VMware vRealize Operations (vROps) Manager SSRF RCE
VMware vRealize Operations (vROps) Manager SSRF RCE
This module exploits a pre-auth SSRF (CVE-2021-21975) and post-auth file write (CVE-2021-21983) in VMware vRealize Operations Manager to leak admin creds and write/execute a JSP payload. CVE-2021-21975 affects the /casa/nodes/thumbprints endpoint, and CVE-2021-21983 affects the /casa/private/config/slice/ha/certificate endpoint. Code execution occurs as the "admin" Unix user. The following vRealize Operations Manager versions are vulnerable: * 7.0.0 * 7.5.0 * 8.0.0, 8.0.1 * 8.1.0, 8.1.1 * 8.2.0 * 8.3.0 Version 8.3.0 is not exploitable for creds and is therefore not supported by this module. Tested successfully against 8.0.1, 8.1.0, 8.1.1, and 8.2.0.
Nuclei
vRealize Operations Manager API - Server-Side Request Forgery
nuclei·CVSS 7.5
CVE-2021-21975 [HIGH] vRealize Operations Manager API - Server-Side Request Forgery
vRealize Operations Manager API - Server-Side Request Forgery
vRealize Operations Manager API is susceptible to server-side request forgery. A malicious actor with network access to the vRealize Operations Manager API can steal administrative credentials or trigger remote code execution using CVE-2021-21983.
Template:
id: CVE-2021-21975
info:
name: vRealize Operations Manager API - Server-Side Request Forgery
author: luci
severity: high
description: vRealize Operations Manager API is susceptible to server-side request forgery. A malicious actor with network access to the vRealize Operations Manager API can steal administrative credentials or trigger remote code execution using CVE-2021-21983.
impact: |
Successful exploitation of this vulnerability could allow an attacker to send arbitr
Unit42
Network Attack Trends: February-April 2021
blogs_unit42·2021-07-01
Network Attack Trends: February-April 2021
## Executive Summary
Unit 42 researchers observed network attack trends, February-April 2021. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity and category. Additionally, we provide insight into how the vulnerabilities are actively exploited in the wild based on real-world data collected from Palo Alto Networks Next-Generation Firewalls. We then draw conclusions about the most commonly exploited vulnerabilities the attackers are using, as well as the severity, category and origin of each attack.
## Network Attack Trends February-April 2021: Analysis of the Latest Published Vulnerabilities
From February-April 2021, a total of 4,969 new Common Vulnerabilities and Exposures (CVE) numbers were registered. To better und
Unit42
Network Attack Trends: February-April 2021
blogs_unit42·2021-07-01
Network Attack Trends: February-April 2021
Threat Research Center
Trend Reports
Vulnerabilities
## Network Attack Trends: February-April 2021
Yue Guan
Lei Xu
Vaibhav Singhal
Brock Mammen
Published: July 1, 2021
Trend Reports
Vulnerabilities
Network security trends
## Executive Summary
Unit 42 researchers observed network attack trends, February-April 2021. In the following sections, we present our analysis of the most recently published vulnerabilities, including the severity and category. Additionally, we provide insight into how the vulnerabilities are actively exploited in the wild based on real-world data collected from Palo Alto Networks Next-Generation Firewalls . We then draw conclusions about the most commonly exploited vulnerabilities the attackers are using, as well as the severity, category and origin of
Checkpoint
5th April – Threat Intelligence Report
blogs_checkpoint·2021-04-05
CVE-2021-21975 5th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Personal information of some 553 million Facebook users from 100 countries has been stolen and published online for free in a hacking forum. The records include full name, Facebook ID, phone number, email, location, bio and more.
Iranian APT group Charming Kitten, linked to the government, has launched a new phishing campaign
Tenable
CVE-2021-21975, CVE-2021-21983: Chained Vulnerabilities in VMware vRealize Operations Could Lead to Unauthenticated Remote Code Execution
blogs_tenable·2021-03-31·CVSS 7.5
[HIGH] CVE-2021-21975, CVE-2021-21983: Chained Vulnerabilities in VMware vRealize Operations Could Lead to Unauthenticated Remote Code Execution
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
A Systematic Approach to Predict the Impact of Cybersecurity Vulnerabilities Using LLMs
arxiv_fulltext·2025-10-19
A Systematic Approach to Predict the Impact of Cybersecurity Vulnerabilities Using LLMs
plain
plain
@IEEEtitlepagestyle
\@oddfoot
\@evenfoot
*3mm [width=2cm]figures/CC-by.pdf
*2mm2.5mm
This work is licensed under a Creative Commons
Attribution 4.0 International (CC BY 4.0) license.
*-69pt
A Systematic Approach to Predict the Impact of Cybersecurity Vulnerabilities Using LLMs
Anders M H
Simula & University of Oslo
Oslo, Norway
[email protected]
Pierre Lison
Norwegian Computing Center
Oslo, Norway
[email protected]
Leon Moonen
Simula Research Laboratory
Oslo, Norway
[email protected]
## Abstract
Vulnerability databases, such as the National Vulnerability Database (NVD), offer detailed descriptions of Common Vulnerabilities and Exposures (CVEs),
but often lack information on their real-world impact, such as the tactics, techniques, and procedures (TTPs) that adv
http://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0004.htmlhttp://packetstormsecurity.com/files/162349/VMware-vRealize-Operations-Manager-Server-Side-Request-Forgery-Code-Execution.htmlhttps://www.vmware.com/security/advisories/VMSA-2021-0004.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21975
2021-03-31
Published
2022-01-18
Added to CISA KEV
Exploited in the wild