QID 375829
Date Published: 2021-12-10
QID 375829: VMware vSphere Replication Authenticated Command Injection Vulnerability (VMSA-2021-0001)
VMware vSphere Replication is a hypervisor-based, asynchronous replication solution for vSphere, enabling disaster recovery and data protection for all virtual machines in your environment.
vSphere Replication contains a post-authentication command injection vulnerability in "Startup Configuration" page.
Affected Versions:
VMware vSphere Replication 8.3.x prior to 8.3.1.2
VMware vSphere Replication 8.2.x prior to 8.2.1.1
VMware vSphere Replication 8.1.x prior to 8.1.2.3
VMware vSphere Replication 6.5.x prior to 6.5.1.5
QID Detection Logic:(Authenticated)
It checks for vulnerable version of VMware vSphere Replication on system
A malicious actor with administrative access in vSphere Replication can execute shell commands on the underlying system. Successful exploitation of this issue may allow authenticated admin user to perform a remote code execution.
- VMSA-2021-0001 -
www.vmware.com/security/advisories/VMSA-2021-0001.html
CVEs related to QID 375829
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2021-0001 |
|