Resource management error in VMware ESXi - CVE-2021-22050
Published: February 15, 2022
Vulnerability identifier: #VU60620
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22050
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within rhttpproxy. A remote attacker can send crafted slow HTTP POST request to the system and perform a denial of service (DoS) attack.
Affected software
VMware ESXi
Cloud Foundation
Dell Enterprise Hybrid Cloud
Dell EMC VxRail Appliance
Cloud Foundation
Dell Enterprise Hybrid Cloud
Dell EMC VxRail Appliance
How to mitigate CVE-2021-22050
Install updates from vendor's website.
VMware ESXi - addressed in versions ESXi650-202110101-SG, ESXi670-202111101-SG, ESXi70U3c-19193900
Cloud Foundation - addressed in versions 3.11, 4.4
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - update to 4.5.471
Cloud Foundation - addressed in versions 3.11, 4.4
Dell Enterprise Hybrid Cloud - update to 4.1.2
Dell EMC VxRail Appliance - update to 4.5.471