CVE-2021-22009
Summary
| CVE | CVE-2021-22009 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-23 12:15:00 UTC |
| Updated | 2022-07-12 17:42:00 UTC |
| Description | The vCenter Server contains multiple denial-of-service vulnerabilities in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit these issues to create a denial of service condition due to excessive memory consumption by VAPI service. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 216265 VMware vCenter Server 7.0 Update 7.0 U2c (VMSA-2021-0020)
- 216266 VMware vCenter Server 6.7 Update 6.7 U3o (VMSA-2021-0020)
- 216267 VMware vCenter Server 6.5 Update 6.5 U3q (VMSA-2021-0020)