S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2021-21985 Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in VMware vCenter Server and VMware Cloud Foundation affects v. VMware vCenter Server (7.x before 7.0 U2b, 6.7 before 6.7 U3n, 6.5 before 6.5 U3p) and VMware Cloud Foundation (4.x before 4.2.1, 3.x before 3.10.2.1).

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-21985
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
VMware vCenter Server and VMware Cloud Foundationby n/a
VMware vCenter Server (7.x before 7.0 U2b, 6.7 before 6.7 U3n, 6.5 before 6.5 U3p) and VMware Cloud Foundation (4.x before 4.2.1, 3.x before 3.10.2.1)
Updated Aug 21, 2026View on NVD →
Detail

VMware vCenter Server is a powerful tool used for managing virtualization infrastructure. It allows administrators to manage virtual machines, storage, and networking across multiple hosts and data centers. VMware Cloud Foundation, on the other hand, is a comprehensive software-defined data center platform that bundles vSphere, vSAN, and NSX into a single solution. It simplifies the deployment and management of the entire stack by providing a unified user interface and automated lifecycle management. 

A critical vulnerability has been discovered in VMware vCenter Server, identified as CVE-2021-21985, which puts organizations at risk of remote code execution attacks. The vulnerability exists due to the lack of input validation in the Virtual SAN Health Check plug-in, which is enabled by default in vCenter Server. Attackers with network access to port 443 can exploit this vulnerability to execute arbitrary commands with elevated privileges on the underlying operating system that hosts vCenter Server.

This vulnerability can lead to complete compromise of vCenter Server and the virtualization infrastructure it manages. Attackers can execute malicious code, steal sensitive data, or disrupt business operations by causing system outages. The consequences can be severe, ranging from reputational damage to financial losses and regulatory fines.

Thanks to the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive vulnerability scanning and management capabilities, including automated discovery, assessment, and remediation of vulnerabilities. It also offers real-time alerts, reports, and dashboards to help organizations stay on top of their security posture and compliance requirements. With s4e.io, organizations can proactively identify and mitigate vulnerabilities before they are exploited by attackers.

 

REFERENCES

Solution Advice

Organizations can protect against this vulnerability by applying the following precautions:

  • Upgrade to the latest version of vCenter Server that includes a patch for this vulnerability.
  • Disable the Virtual SAN Health Check plug-in if it is not required.
  • Restrict network access to vCenter Server to trusted sources.
  • Implement intrusion detection and prevention systems to monitor for suspicious activities.
  • Follow best practices for secure configuration and hardening of vCenter Server and its underlying operating system.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.