Resource exhaustion in vCenter Server - CVE-2021-22010

 

Resource exhaustion in vCenter Server - CVE-2021-22010

Published: September 21, 2021


Vulnerability identifier: #VU56799
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22010
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources within the VPXD (Virtual Provisioning X Daemon) service. A remote attacker can send a secially crafted HTTP request to port 443/TCP and consume all available memory resources.


Affected software

vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
IBM Cloud Pak System
Cloud Foundation
Dell EMC VxRail Appliance

How to mitigate CVE-2021-22010

Install updates from vendor's website.

vCenter Server - addressed in versions 6.7 U3o, 7.0 U2c
EMC Integrated Data Protection Appliance - update to 2.7.0
IBM Cloud Pak System - update to 2.3.3.4
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241

External References

Related Security Bulletins