CVE-2021-22006
The vCenter Server contains a reverse proxy bypass vulnerability due to the way the endpoints handle the URI. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to access restricted endpoints.
- Affected products
- Vmware Vcenter, Vcenter Server
- Vmware Cloud Foundation
- < 5.0
- Vmware Vcenter Server
- = 6.7, 7.0
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 6.4% (93th percentile)
- NVD status
- Modified
- Published
- 2021-09-23
CVE-2021-22006 at NVD
4 known exploits for CVE-2021-22006
Proof-of-concept code and exploit modules indexed by Sploitus