Authentication Bypass Vulnerability in Small Footprint CIM Broker for VMware ESXi
CVE-2021-21994

9.8CRITICAL

Key Information:

Vendor
Vmware
Vendor
CVE Published:
13 July 2021

Summary

The Small Footprint CIM Broker (SFCB) integrated within VMware ESXi is susceptible to an authentication bypass vulnerability. Attackers with network access to TCP port 5989 can exploit this flaw by sending crafted requests, enabling them to gain unauthorized access to sensitive resources. This security risk necessitates immediate attention to ensure the integrity and protection of the ESXi environment.

Affected Version(s)

VMware ESXi and VMware Cloud Foundation VMware ESXi(7.0 before ESXi70U2-17630552, 6.7 before ESXi670-202103101-SG, 6.5 before ESXi650-202107401-SG) and VMware Cloud Foundation (4.x, 3.x before 3.10.2)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.