THREAT OPS › Threat News › [NVD] CVE-2021-21985 (CRITICAL 9.8) — The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute com
[NVD] CVE-2021-21985 (CRITICAL 9.8) — The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute com
CVE-2021-21985 CVSS: 9.8 CRITICAL Published: 2021-05-26T15:15:07.937
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlyi
Indicators of compromise
- CVE-2021-21985cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-21985