PT-2021-2362 · Vmware · Vmware View Planner
Mikhail Klyuchnikov
·
Published
2021-03-02
·
Updated
2023-08-08
·
CVE-2021-21978
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
VMware View Planner versions prior to 4.6 Security Patch 1
Description
The issue is related to the lack of authorization and improper input validation in the logupload web application of VMware View Planner, allowing an unauthorized attacker with network access to upload and execute a specially crafted file, leading to remote code execution within the logupload container. This can be exploited by an attacker to execute arbitrary code.
Recommendations
For versions prior to 4.6 Security Patch 1, apply the 4.6 Security Patch 1 to resolve the issue. As a temporary workaround, consider restricting access to the logupload web application to minimize the risk of exploitation. Avoid using the logupload feature until the issue is resolved.
Exploit
Fix
Unrestricted File Upload
Missing Authorization
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vmware View Planner