S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-21973 Scanner

CVE-2021-21973 scanner - Server-Side Request Forgery (SSRF) vulnerability in VMware vCenter Server and VMware Cloud Foundation

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-21973
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
VMware vCenter Serverby n/a
7.x before 7.0 U1c
VMware Cloud Foundationby n/a
4.x before 4.2
Updated Aug 21, 2026View on NVD →
Detail

VMware vCenter Server and VMware Cloud Foundation are virtualization solutions that allow organizations to manage their IT infrastructure in an efficient and cost-effective manner. VMware vCenter Server acts as the central hub for managing virtual machines, providing a single point of control for tasks such as provisioning, monitoring, and scaling. Meanwhile, VMware Cloud Foundation is an integrated software stack that combines compute, storage, and networking with automation and lifecycle management capabilities.

However, these products are not without their weaknesses. One such vulnerability is CVE-2021-21973, which was recently discovered in the vSphere Client (HTML5) component of VMware vCenter Server and VMware Cloud Foundation. This vulnerability allows attackers with network access to port 443 to exploit a server-side request forgery (SSRF) flaw due to a lack of proper URL validation in a vCenter Server plugin.

If this vulnerability is successfully exploited, an attacker can gain access to sensitive information stored within the virtual environment, including virtual machines, network devices, and other resources. This information could be used for a variety of malicious purposes, such as conducting further attacks, sabotaging operations, or stealing confidential data.

By using the advanced features of the s4e.io platform, you can learn about vulnerabilities like CVE-2021-21973 in your digital assets quickly and easily. With detailed analysis and expert guidance, you can stay one step ahead of attackers and ensure that your virtual environment remains secure and reliable. So why wait? Sign up today and take control of your cybersecurity posture!

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability, including:

  • Implementing the relevant patches issued by VMware.
  • Restricting network access to the vCenter Server and VMware Cloud Foundation to authorized personnel only.
  • Monitoring network traffic for unusual activity that could be indicative of an attack.
  • Limiting the capabilities of vCenter Server plugins to only those that are strictly necessary.
  • Conducting regular security assessments and penetration testing to identify and mitigate vulnerabilities before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-21973 scanner - Server-Side Request Forgery (SSRF) vulnerability in VMware vCenter Server and VMware Cloud Foundation | S4E