Authentication Bypass Vulnerability in Small Footprint CIM Broker for VMware ESXi
CVE-2021-21994
9.8CRITICAL
Key Information:
- Vendor
- Vmware
- Vendor
- CVE Published:
- 13 July 2021
Summary
The Small Footprint CIM Broker (SFCB) integrated within VMware ESXi is susceptible to an authentication bypass vulnerability. Attackers with network access to TCP port 5989 can exploit this flaw by sending crafted requests, enabling them to gain unauthorized access to sensitive resources. This security risk necessitates immediate attention to ensure the integrity and protection of the ESXi environment.
Affected Version(s)
VMware ESXi and VMware Cloud Foundation VMware ESXi(7.0 before ESXi70U2-17630552, 6.7 before ESXi670-202103101-SG, 6.5 before ESXi650-202107401-SG) and VMware Cloud Foundation (4.x, 3.x before 3.10.2)
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved