CVE-2021-21994
published 2021-07-13CVE-2021-21994: SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may…
PriorityP266critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.16%
63.5th percentile
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | >= 3.0 < 3.10.2 | 3.10.2 |
| vmware | cloud_foundation | >= 4.0 < 4.3 | 4.3 |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
| vmware | esxi | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unexpected or unauthenticated connections to TCP port 5989 (SFCB/CIM Broker) on ESXi hosts, which may indicate exploitation attempts of the authentication bypass vulnerability. ↗
- →Alert on any specially crafted requests targeting the SFCB (Small Footprint CIM Broker) service on ESXi that result in successful authentication without valid credentials. ↗
- ·Exploitation requires network-level access to port 5989 on the ESXi host; restricting or firewalling this port reduces attack surface. ↗
- ·Affected products include VMware ESXi, VMware Cloud Foundation, and VMware vSphere — all deployments of these products running SFCB should be assessed. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4643-h6pq-84f9: SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-21994 [CRITICAL] CWE-287 GHSA-4643-h6pq-84f9: SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
VMware
VMware ESXi updates address authentication and denial of service vulnerabilities (CVE-2021-21994, CVE-2021-21995)
vendor_vmware·2021-07-13·CVSS 9.8
CVE-2021-21994 [CRITICAL] VMware ESXi updates address authentication and denial of service vulnerabilities (CVE-2021-21994, CVE-2021-21995)
VMSA-2021-0014: VMware ESXi updates address authentication and denial of service vulnerabilities (CVE-2021-21994, CVE-2021-21995)
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability.VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.0.
CVEs: CVE-2021-21994, CVE-2021-21995
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vSphere
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-13
Published