Improper Authentication in vCenter Server - CVE-2021-22011

 

Improper Authentication in vCenter Server - CVE-2021-22011

Published: September 21, 2021


Vulnerability identifier: #VU56800
CSH Severity: Medium
CVSS v4: 8.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22011
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to missing authentication for an API endpoint in vCenter Server Content Library. A remote non-authenticated attacker with access to port 443/TCP can gain unauthorized access to the system and perform unauthenticated VM network setting manipulation.


Affected software

vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
IBM Cloud Pak System
Cloud Foundation
Dell EMC VxRail Appliance

How to mitigate CVE-2021-22011

Install updates from vendor's website.

vCenter Server - addressed in versions 6.5 U3q, 6.7 U3o, 7.0 U2d
EMC Integrated Data Protection Appliance - update to 2.7.0
IBM Cloud Pak System - update to 2.3.3.4
Cloud Foundation - addressed in versions 3.10.2.2, 4.3.1
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241

External References

Related Security Bulletins