Input validation error in Cloud Foundation and vCenter Server - CVE-2021-21985
Published: May 26, 2021 / Updated: February 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input within the Virtual SAN Health Check plug-in, which is enabled by default. A remote non-authenticated attacker can send a specially crafted HTTP request to the vSphere Client available at port 443/tcp and execute arbitrary commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
Affected software
vCenter Server
Dell Enterprise Hybrid Cloud
IBM Cloud Pak System
PowerFlex Appliance
EMC Integrated Data Protection Appliance
Dell EMC VxRail Appliance
How to mitigate CVE-2021-21985
vCenter Server - addressed in versions 6.5 U3p, 6.7 U3n, 7.0 U2b
IBM Cloud Pak System - update to 2.3.3.4
Dell Enterprise Hybrid Cloud - update to 4.1.2
PowerFlex Appliance - addressed in versions Intelligent_Catalog_37_361_00_r14, Intelligent_Catalog_37_355_00_r16
EMC Integrated Data Protection Appliance - update to 2.7.0
Dell EMC VxRail Appliance - update to 4.5.461
Links to Public Exploits and PoC-codes
- Exploit #7000 - CVE-2021-21985_PoC (VMWARE VCENTER SERVER VIRTUAL SAN HEALTH CHECK PLUG-IN RCE (CVE-2021-21985) ) (November 11, 2021)
- Exploit #6535 - CVE-2021-21985 (cve-2021-21985 powershell xploits for leaving off the land 'n shit) (July 12, 2021)
- Exploit #6533 - VMware vCenter Server Virtual SAN Health Check Plugin RCE (July 12, 2021)
- Exploit #6526 - CVE-2021-21985 () (July 8, 2021)
- Exploit #5533 - Project_CVE-2021-21985_PoC () (June 6, 2021)
- Exploit #5526 - CVE-2021-21985 (CVE-2021-21985 vmware 6.7-9.8 RCE) (June 6, 2021)
- Exploit #5523 - cve-2021-21985_exp (cve-2021-21985 exploit) (June 3, 2021)
- Exploit #5522 - CVE-2021-21985 (CVE-2021-21985 VMware vCenter Server远程代码执行漏洞 EXP (更新可回显EXP)) (June 3, 2021)
- Exploit #5514 - CVE-2021-21985-Checker (CVE-2021-21985 Checker.) (June 1, 2021)
- Exploit #5510 - CVE-2021-21985_PoC () (June 1, 2021)
- Exploit #5509 - CVE-2021-21985 (This script check the CVE-2021-21985 vulnerability and patch on vCenter Server.) (June 1, 2021)
- Exploit #5507 - CVE-2021-21985 () (May 31, 2021)
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware vCenter Server
- Dell EMC Enterprise Hybrid Cloud update for VMware products
- Multiple Vulnerabilities IBM Cloud Pak System
- Multiple vulnerabilities in Dell Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Multiple vulnerabilities in Dell VxRail Appliance