S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-21972 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in VMware vCenter Server and VMware Cloud Foundation affects v. VMware vCenter Server 7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n and VMware Cloud Foundation 4.x before 4.2 and 3.x before 3.10.1.2.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-21972
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
VMware vCenter Serverby n/a
7.x before 7.0 U1c
VMware Cloud Foundationby n/a
4.x before 4.2
Updated Aug 21, 2026View on NVD →
Detail

The VMware vCenter Server and VMware Cloud Foundation are essential products designed to ensure efficient management of data center infrastructure. The vCenter Server allows administrators to control multiple virtual machines from a single centralized location, while Cloud Foundation enhances the scalability and flexibility of VMware-based private and hybrid cloud deployments. These products are particularly suitable for enterprises looking to streamline their data center operations and optimize resource utilization.

However, security researchers have recently detected a significant vulnerability in these products, identified as CVE-2021-21972. This remote code execution vulnerability can be exploited by attackers with access to port 443, enabling them to execute arbitrary commands with unrestricted privileges on the operating system hosting vCenter Server. This vulnerability affects various versions of VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n), as well as VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

If exploited, the CVE-2021-21972 vulnerability can lead to severe consequences such as complete data loss, data theft, and system compromise. Attackers can execute malicious code, modify files, and delete sensitive data from an extensive range of connected virtual machines. Subsequently, they can gain unauthorized access to sensitive information and infiltrate further into the network, posing potential threats to business operations and reputation.

By identifying security vulnerabilities that put their digital assets at risk, organizations can take appropriate actions and precautions to avoid data breaches and system compromise. Thanks to the pro features of the s4e.io platform, users can access information about vulnerabilities such as CVE-2021-21972 quickly and effectively. With the platform's expansive database of security threats, users can ensure constant monitoring and protection of their digital assets.

 

REFERENCES

Solution Advice

To mitigate the risk of exploitation, here are several precautions that can be taken to ensure better protection against CVE-2021-21972:

  • Patch VMware vCenter Server and VMware Cloud Foundation as soon as possible.
  • Limit network access to port 443 to trusted entities only.
  • Monitor network traffic and system logs for any signs of suspicious activity.
  • Use strong passwords and two-factor authentication to prevent unauthorized access.
  • Consider limiting permissions to critical user accounts to minimize the impact of an attack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-21972 scanner - Remote Code Execution (RCE) vulnerability in VMware vCenter Server and VMware Cloud Foundation | S4E