Incorrect default permissions in vCenter Server - CVE-2021-22015
Published: September 21, 2021 / Updated: December 5, 2022
Vulnerability identifier: #VU56804
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22015
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for files and folders that are set by the system. A local user with access to the system can escalate privilege to root on vCenter Server Appliance.
Affected software
vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Cloud Foundation
Dell EMC VxRail Appliance
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Cloud Foundation
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22015
Install updates from vendor's website.
vCenter Server - addressed in versions 6.5 U3q, 6.7 U3o, 7.0 U2c
EMC Integrated Data Protection Appliance - update to 2.7.0
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241
EMC Integrated Data Protection Appliance - update to 2.7.0
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware vCenter Server
- Multiple vulnerabilities in VMware vCloud Foundation
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Dell EMC Enterprise Hybrid Cloud update for VMware products
- Multiple vulnerabilities in Dell EMC PowerProtect DP Series (Integrated Data Protection Appliance)