QID 216265

Date Published: 2021-09-22

QID 216265: VMware vCenter Server 7.0 Update 7.0 U2c (VMSA-2021-0020)

VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.

The vCenter Server contains multiple vulnerabilities. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.

Affected Versions: vCenter Server 7.0
QID Detection Logic (Unauthenticated):
This QID checks for vulnerable versions of VMware vCenter Server with build version using web service present on target.
QID Detection Logic (Auth):
This QID checks for a workaround in the Linux OS.
Note: We only support Linux authentication if the customer has a default bash shell assigned to the user.

This update addresses multiple vulnerabilities as stated below:
vCenter Server file upload vulnerability (CVE-2021-22005)
vCenter Server local privilege escalation vulnerability (CVE-2021-21991)
vCenter Server SSRF vulnerability (CVE-2021-21993)
vCenter Server XML parsing denial-of-service vulnerability (CVE-2021-21992)
vCenter Server reverse proxy bypass vulnerability (CVE-2021-22006)
vCenter Server local information disclosure vulnerability (CVE-2021-22007)
vCenter Server VPXD denial of service vulnerability (CVE-2021-22010)
vCenter Server information disclosure vulnerability (CVE-2021-22008)
vCenter Server VAPI multiple denial of service vulnerabilities (CVE-2021-22009)
vCenter Server authenticated code execution vulnerability (CVE-2021-22014)
vCenter Server improper permission local privilege escalation vulnerabilities (CVE-2021-22015)
vCenter Server denial of service vulnerability (CVE-2021-22019)
vCenter Server Analytics service denial-of-service Vulnerability (CVE-2021-22020)

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Vmware has released patch for VMware vCenter Server 7.0 , visit VMware vCenter Server 7.0 Update 2c Release Notes

    Refer to VMware advisory VMSA-2021-0020 for more information.

    Workaround:
    Please refer to the KB article KB85717 for more information.

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2021-0020 URL Logo www.vmware.com/security/advisories/VMSA-2021-0020.html