PT-2021-4147 · Vmware · Vcenter Server+1

George Noseevich

+2

·

Published

2021-09-21

·

Updated

2026-02-07

·

CVE-2021-22005

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions VMware vCenter Server versions prior to the fixed version
Description The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file. Thousands of potentially vulnerable servers are accessible through the Internet and are at risk of attacks. There have been real-world incidents where this issue was exploited, including an attack on the European retail giant MediaMarkt, which resulted in a ransom demand of $240 million and the disruption of IT systems and store operations.
Recommendations For versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the Analytics service and port 443 to minimize the risk of exploitation. Additionally, follow best practices such as regularly updating software, being cautious when using online conferencing applications, and not attempting to hide data breaches to reduce the risk of cyber incidents.

Exploit

Fix

Path traversal

RCE

Weakness Enumeration

Related Identifiers

BDU:2021-04740
CVE-2021-22005

Affected Products

Vmware Vcenter
Vcenter Server