QID 216264
Date Published: 2021-09-20
QID 216264: VMware ESXi 6.5 Patch Release ESXi650-202107401-SG Missing (VMSA-2021-0014)
VMware ESXi is an enterprise level computer virtualization product.
SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability.
Affected Versions:
VMware ESXi 6.5 prior to build 18071574
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware ESXi with build version using web service present on the target.
QID Detection Logic (Authenticated):
This QID checks whether the SFCB service (CIM Server) service and SLP service are off as mentioned in the workaround. If both services are off, QID will not flag.
A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.
Refer to VMware advisory VMSA-2021-0014 for more information.
Workaround:
For CVE-2021-21994
Disable the SFCB service (CIM Server) on the ESX/ESXi host
Please visit here for more information.
For CVE-2021-21995
Disable the SLP service on the ESX/ESXi host
Please visit here for more information.
- VMSA-2021-0014 -
www.vmware.com/security/advisories/VMSA-2021-0014.html
CVEs related to QID 216264
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMware ESXi 6.5 ESXi650-202107401-SG |
|