5.3

CVE-2021-22017

Warnung
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ vCenter Server Version 6.7 Update -

10.01.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

VMware vCenter Server Improper Access Control

Schwachstelle

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 49.18% 0.988
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CISA-ADP 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22017
US Government Resource