Input validation error in Cloud Foundation and vCenter Server - CVE-2021-21985

 

Input validation error in Cloud Foundation and vCenter Server - CVE-2021-21985

Published: May 26, 2021 / Updated: February 20, 2022


Vulnerability identifier: #VU53595
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21985
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input within the Virtual SAN Health Check plug-in, which is enabled by default. A remote non-authenticated attacker can send a specially crafted HTTP request to the vSphere Client available at port 443/tcp and execute arbitrary commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.


Affected software

Cloud Foundation
vCenter Server
Dell Enterprise Hybrid Cloud
IBM Cloud Pak System
PowerFlex Appliance
EMC Integrated Data Protection Appliance
Dell EMC VxRail Appliance

How to mitigate CVE-2021-21985

Install updates from vendor's website.

Cloud Foundation - addressed in versions 3.10.2.1, 4.2.1
vCenter Server - addressed in versions 6.5 U3p, 6.7 U3n, 7.0 U2b
IBM Cloud Pak System - update to 2.3.3.4
Dell Enterprise Hybrid Cloud - update to 4.1.2
PowerFlex Appliance - addressed in versions Intelligent_Catalog_37_361_00_r14, Intelligent_Catalog_37_355_00_r16
EMC Integrated Data Protection Appliance - update to 2.7.0
Dell EMC VxRail Appliance - update to 4.5.461

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins