PT-2021-2362 · Vmware · Vmware View Planner

Mikhail Klyuchnikov

·

Published

2021-03-02

·

Updated

2023-08-08

·

CVE-2021-21978

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VMware View Planner versions prior to 4.6 Security Patch 1
Description The issue is related to the lack of authorization and improper input validation in the logupload web application of VMware View Planner, allowing an unauthorized attacker with network access to upload and execute a specially crafted file, leading to remote code execution within the logupload container. This can be exploited by an attacker to execute arbitrary code.
Recommendations For versions prior to 4.6 Security Patch 1, apply the 4.6 Security Patch 1 to resolve the issue. As a temporary workaround, consider restricting access to the logupload web application to minimize the risk of exploitation. Avoid using the logupload feature until the issue is resolved.

Exploit

Fix

Unrestricted File Upload

Missing Authorization

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-01600
CVE-2021-21978

Affected Products

Vmware View Planner