5.3
CVE-2021-22017
- EPSS 75.51%
- Veröffentlicht 23.09.2021 13:15:08
- Zuletzt bearbeitet 30.10.2025 20:05:09
- Quelle security@vmware.com
- CVE-Watchlists
- Unerledigt
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Vcenter Server Version6.7 Update-
10.01.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
VMware vCenter Server Improper Access Control
SchwachstelleRhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 75.51% | 0.988 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|