Input validation error in vCenter Server - CVE-2021-22019
Published: September 21, 2021
Vulnerability identifier: #VU56808
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22019
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in VAPI (vCenter API) service. A remote attacker can pass specially crafted crafted jsonrpc message to port 5480/TCP and perform a denial of service (DoS) attack.
Affected software
vCenter Server
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Cloud Foundation
Dell EMC VxRail Appliance
Dell Enterprise Hybrid Cloud
EMC Integrated Data Protection Appliance
Cloud Foundation
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22019
Install updates from vendor's website.
vCenter Server - addressed in versions 6.5 U3q, 6.7 U3o, 7.0 U2c
EMC Integrated Data Protection Appliance - update to 2.7.0
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241
EMC Integrated Data Protection Appliance - update to 2.7.0
Cloud Foundation - update to 3.10.2.2
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - addressed in versions 4.5.463, 4.7.536, 7.0.241
External References
Related Security Bulletins
- Multiple vulnerabilities in VMware vCenter Server
- Multiple vulnerabilities in VMware vCloud Foundation
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Dell EMC Enterprise Hybrid Cloud update for VMware products
- Multiple vulnerabilities in Dell EMC PowerProtect DP Series (Integrated Data Protection Appliance)