Improper Authentication in VMware ESXi - CVE-2021-21994

 

Improper Authentication in VMware ESXi - CVE-2021-21994

Published: July 13, 2021


Vulnerability identifier: #VU54814
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-21994
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests in SFCB (Small Footprint CIM Broker). A remote attacker can send specially crafted requests to port 5989/tcp, bypass SFCB authentication and gain unauthorized access to the system.


Affected software

VMware ESXi
IBM Cloud Pak System
Cloud Foundation
Dell Enterprise Hybrid Cloud
PowerFlex rack
Dell EMC VxRail Appliance

How to mitigate CVE-2021-21994

Install updates from vendor's website.

VMware ESXi - addressed in versions ESXi650-202107401-SG, ESXi670-202103101-SG, ESXi70U2-17630552
IBM Cloud Pak System - update to 2.3.3.4
Cloud Foundation - update to 3.10.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
PowerFlex rack - addressed in versions 3.3.10.0, 3.4.4.2, 3.5.4.2, 3.6.1.0
Dell EMC VxRail Appliance - update to 4.5.462

External References

Related Security Bulletins