S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-22005 Scanner

CVE-2021-22005 scanner - File Upload vulnerability in VMware vCenter Server, VMware Cloud Foundation

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-22005
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
VMware vCenter Server, VMware Cloud Foundationby n/a
VMware vCenter Server(7.x before 7.0 U2c and 6.7 before 6.7 U3o) and VMware Cloud Foundation (4.x before 4.3 and 3.x before 3.10.2.2)
Updated Aug 21, 2026View on NVD →
Detail

VMware vCenter Server is a centralized management platform for VMware vSphere environments. It enables the management of virtual machines and hosts, and also allows for the administration of storage, network, and security policies. VMware Cloud Foundation is a platform that combines VMware vSphere, VMware NSX, and VMware vSAN to provide a complete software-defined data center solution. Its goal is to simplify the deployment and management of hybrid cloud platforms.

The CVE-2021-22005 vulnerability detected in VMware vCenter Server's Analytics service is an arbitrary file upload vulnerability. Essentially, any malicious actor with network access to port 443 of the affected vCenter Server can exploit this vulnerability by uploading a specially crafted file. This can allow the actor to execute code on the vCenter Server.

If exploited, this vulnerability can lead to significant security risks. Attackers can potentially gain unauthorized access to critical data, and even take control of the entire vCenter Server infrastructure. This can result in the theft of sensitive information, misconfiguration of virtual machines and hosts, or even ransom demands.

By using the pro features of the s4e.io platform, readers can quickly and easily learn about vulnerabilities in their digital assets. With our help, they can stay on top of the latest security threats and ensure that their networks are protected from potential cyber attacks. Our platform offers comprehensive vulnerability scanning and remediation, so organizations can keep their data safe and secure at all times.

 

REFERENCES

Solution Advice

There are some precautions that organizations can take to protect themselves against this vulnerability. Here are a few key steps:

  • Apply the latest patches and security updates for VMware vCenter Server. VMware has released a patch for this vulnerability, and it is recommended that organizations install it as soon as possible.
  • Restrict network access to the vCenter Server to authorized user groups only. This can help prevent unauthorized access to the server.
  • Implement strong password policies for all users who have access to the vCenter Server. This can help prevent brute force attacks and unauthorized access.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-22005 scanner - File Upload vulnerability in VMware vCenter Server, VMware Cloud Foundation | S4E