SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-22017

VMware vCenter Server Improper Access Control

KEVMEDIUM 5.3EPSS 49.2%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 January 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
49.18% probability · 99th percentile
CISA KEV
Listed 10 January 2022 · due 24 January 2022
Affected
vmware/vcenter server
Source
security@vmware.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-22017

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.