CVE-2021-21992
published 2021-09-22CVE-2021-21992: The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the…
PriorityP431medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.98%
58.1th percentile
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service condition on the vCenter Server host.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 3.0 < 3.10.2.2 | 3.10.2.2 |
| vmware | cloud_foundation | >= 4.0 < 4.3 | 4.3 |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
| vmware | vcenter_server | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter Server updates address multiple security vulnerabilities
vendor_vmware·2021-09-21·CVSS 7.8
CVE-2021-21991 [HIGH] VMware vCenter Server updates address multiple security vulnerabilities
VMSA-2021-0020: VMware vCenter Server updates address multiple security vulnerabilities
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2021-21991, CVE-2021-21992, CVE-2021-21993, CVE-2021-22005, CVE-2021-22006, CVE-2021-22007, CVE-2021-22008, CVE-2021-22009, CVE-2021-22010, CVE-2021-22011, CVE-2021-22012, CVE-2021-22013, CVE-2021-22014, CVE-2021-22015, CVE-2021-22016, CVE-2021-22017, CVE-2021-22018, CVE-2021-22019, CVE-2021-22020
Affected products: VMware Cloud Foundation, VMware vCenter Server, VMware vSphere
GHSA
GHSA-mhm3-qvq8-3fc6: The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing
ghsa_unreviewed·2022-05-24
CVE-2021-21992 [MEDIUM] CWE-400 GHSA-mhm3-qvq8-3fc6: The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service condition on the vCenter Server host.
No detection rules found.
No public exploits indexed.
2021-09-22
Published