Resource exhaustion in vCenter Server - CVE-2021-22009

 

Resource exhaustion in vCenter Server - CVE-2021-22009

Published: September 21, 2021


Vulnerability identifier: #VU56798
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22009
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the VAPI (vCenter API) service. A remote attacker can send specially crafted HTTP request to port 443/TCP and perform a denial of service (DoS) attack.


Affected software

vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
IBM Cloud Pak System
Cloud Foundation
Dell EMC VxRail Appliance

How to mitigate CVE-2021-22009

Install updates from vendor's website.

vCenter Server - addressed in versions 6.5 U3q, 6.7 U3o, 7.0 U2c
EMC Integrated Data Protection Appliance - update to 2.7.0
IBM Cloud Pak System - update to 2.3.3.4
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241

External References

Related Security Bulletins