THREATOPS
THREAT OPSThreat News › [NVD] CVE-2021-21985 (CRITICAL 9.8) — The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute com

[NVD] CVE-2021-21985 (CRITICAL 9.8) — The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute com

lownvdPublished 2021-05-26

CVE-2021-21985 CVSS: 9.8 CRITICAL Published: 2021-05-26T15:15:07.937

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlyi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-21985