CVE-2021-22002

Severity
9.8CRITICAL
EPSS
0.4%
top 41.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateMay 24

Description

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

NVDvmware/workspace_one_access20.01, 20.10, 20.10.01+2
NVDvmware/identity_manager4 versions+3
NVDvmware/cloud_foundation5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-35g3-x9xw-f42c: VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a c2022-05-24
CVEList
CVE-2021-22002: VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a c2021-08-31

📋Vendor Advisories

1
VMware
VMware Workspace ONE Access, Identity Manager and vRealize Automation address multiple vulnerabilities (CVE-2021-22002, CVE-2021-22003)2021-08-05
CVE-2021-22002 (CRITICAL CVSS 9.8) | VMware Workspace ONE Access and Ide | cvebase.io