QID 730212

QID 730212: VMware vCenter Server Arbitrary File Upload Vulnerability (VMSA-2021-0020)(Unauthenticated)

VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.

VMware has fixed an arbitrary file upload vulnerability in the Analytics service of VMware vCenter. An attacker with network access to port 443 running on vCenter Server can exploit this vulnerability and execute code on vCenter Server by uploading a specially crafted file.

Affected Versions:
VMware vCenter Server 7.0
VMware vCenter Server 6.7

QID Detection Logic (Unauthenticated):
This QID sends a specially crafted HTTP POST request to "/analytics/telemetry/ph/api/hyper/send" endpoint to identify vulnerable targets.

Successful exploitation of the vulnerability will allow an attacker to execute code on vCenter Server by uploading a specially crafted file.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vmware has released patch for VMware vCenter Server 7.0 , visit VMware vCenter Server 7.0 Update 2c Release Notes and vCenter Server 6.7, visit VMware vCenter Server 6.7 Update 3o Release Notes

    Refer to VMware advisory VMSA-2021-0020 for more information.

    Workaround:
    Please refer to the KB article KB85717 for more information.

    CVEs related to QID 730212

    Software Advisories
    Advisory ID Software Component Link
    VMSA-2021-0020 URL Logo www.vmware.com/security/advisories/VMSA-2021-0020.html