CISA Known Exploited Vulnerability

CVE-2021-22005 Ransomware

VMware · vCenter Server

VMware vCenter Server File Upload Vulnerability

Date added
BOD 22-01 due date
CWE CWE-23
Ransomware Known

CISA description

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

Required action

Apply updates per vendor instructions.