cbcvebase.
CVE-2021-22005
published 2021-09-23

CVE-2021-22005: The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
100.00%
100.0th percentile
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

Affected

4 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 3.0 < 5.05.0
vmwarevcenter_server
vmwarevcenter_server
vmwarevcenter_server

Detection & IOCsextracted from sources · hover to see the quote

port443
snort
SIDs: 58217 - 58219
  • Monitor for POST requests to vCenter Analytics service endpoints on port 443 containing invalid JSON or empty JSON objects — these match the VMware patching script's vulnerability check pattern used by scanners probing for CVE-2021-22005.
  • Alert on POST requests to vCenter vulnerable endpoints containing valid, parsable, or non-empty payloads — these indicate active file upload exploitation attempts beyond mere scanning.
  • Detect FaceFish backdoor activity by monitoring for creation of libs.so and modification of /etc/ld.so.preload, followed by an sshd service restart — the backdoor injects into sshd via ld.so.preload.
  • Flag scanning traffic originating from Tor exit nodes targeting vCenter Server port 443, as the majority of CVE-2021-22005 vulnerability checks observed were egressing via Tor.
  • CVE-2021-22005 exploitation can result in a reverse shell on the vCenter server; monitor for unexpected outbound connections from vCenter processes after file upload activity.
  • ·CVE-2021-22005 is exploitable regardless of vCenter Server configuration — the arbitrary file upload vulnerability in the Analytics service works irrespective of configuration settings.
  • ·Affected vCenter Server versions include 6.7 and 7.0 deployments exposed to the internet; prioritize patching internet-facing instances.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.