Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-21991

EPSS 0.19% · P41
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-21991

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
VMware vCenter Server 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
VMware vCenter Server是美国威睿(VMware)公司的一套服务器和虚拟化管理软件。该软件提供了一个用于管理VMware vSphere环境的集中式平台,可自动实施和交付虚拟基础架构。 VMware vCenter Server 存在权限许可和访问控制问题漏洞,该漏洞源于vCenter Server处理会话令牌的方式存在问题。本地用户可以通过vSphere Client (HTML5)或vCenter Server vSphere Web Client (FLEX Flash)将用户权限
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-VMware vCenter Server, VMware Cloud Foundation VMware vCenter Server(7.x before 7.0 U2c, 6.7 before 6.7 U3o and 6.5 before 6.5 U3q) and VMware Cloud Foundation (4.x before 4.3 and 3.x before 3.10.2.2) -

II. Public POCs for CVE-2021-21991

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-21991

登录查看更多情报信息。

Same Patch Batch · n/a · 2021-09-22 · 14 CVEs total

CVE-2020-23481CMS Made Simple 跨站脚本漏洞
CVE-2020-23478Leo-Editor 安全漏洞
CVE-2020-23469gedit 安全漏洞
CVE-2021-21992VMware vCenter Server 资源管理错误漏洞
CVE-2019-6288Edgecore ECS2020 命令注入漏洞
CVE-2021-40684Talend ESB 授权问题漏洞
CVE-2021-40875Gurock Software Gurock TestRail 信息泄露漏洞
CVE-2021-37927Zoho Corporation ADManager Plus 数据伪造问题漏洞
CVE-2021-37925ZOHO ManageEngine ADManager Plus 操作系统命令注入漏洞
CVE-2021-39404MaianAffiliate 跨站脚本漏洞
CVE-2021-36260Hikvision Web Server 操作系统命令注入漏洞
CVE-2021-38112Amazon WorkSpaces 参数注入漏洞
CVE-2021-3583Red Hat Ansible 代码注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2021-21991

No comments yet


Leave a comment