Security News > 2021 > September > VMware Warns of Critical File Upload Vulnerability Affecting vCenter Server

VMware Warns of Critical File Upload Vulnerability Affecting vCenter Server
2021-09-21 20:22

The most urgent among them is an arbitrary file upload vulnerability in the Analytics service that impacts vCenter Server 6.7 and 7.0 deployments.

"A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file," the company noted, adding "This vulnerability can be used by anyone who can reach vCenter Server over the network to gain access, regardless of the configuration settings of vCenter Server."

CVE-2021-22005 - vCenter Server file upload vulnerability.

CVE-2021-22013 - vCenter Server file path traversal vulnerability.

CVE-2021-22018 - vCenter Server file deletion vulnerability.

CVE-2021-22010 - vCenter Server VPXD denial of service vulnerability.


News URL

http://feedproxy.google.com/~r/TheHackersNews/~3/r8ZzAQq3YU4/vmware-warns-of-critical-file-upload.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-09-23 CVE-2021-22018 Unspecified vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in.
network
low complexity
vmware
6.5
2021-09-23 CVE-2021-22013 Path Traversal vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API.
network
low complexity
vmware CWE-22
7.5
2021-09-23 CVE-2021-22010 Resource Exhaustion vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains a denial-of-service vulnerability in VPXD service.
network
low complexity
vmware CWE-400
7.5
2021-09-23 CVE-2021-22005 Path Traversal vulnerability in VMWare Cloud Foundation and Vcenter Server
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
network
low complexity
vmware CWE-22
critical
9.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Vmware 146 11 222 256 102 591