QID 730212
QID 730212: VMware vCenter Server Arbitrary File Upload Vulnerability (VMSA-2021-0020)(Unauthenticated)
VMware vCenter Server is a server management solution that helps IT admins manage virtualized hosts and virtual machines in enterprise environments via a single console.
VMware has fixed an arbitrary file upload vulnerability in the Analytics service of VMware vCenter. An attacker with network access to port 443 running on vCenter Server can exploit this vulnerability and execute code on vCenter Server by uploading a specially crafted file.
Affected Versions:
VMware vCenter Server 7.0
VMware vCenter Server 6.7
QID Detection Logic (Unauthenticated):
This QID sends a specially crafted HTTP POST request to "/analytics/telemetry/ph/api/hyper/send" endpoint to identify vulnerable targets.
Successful exploitation of the vulnerability will allow an attacker to execute code on vCenter Server by uploading a specially crafted file.
Refer to VMware advisory VMSA-2021-0020 for more information.
Workaround:
Please refer to the KB article KB85717 for more information.
- VMSA-2021-0020 -
www.vmware.com/security/advisories/VMSA-2021-0020.html
CVEs related to QID 730212
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| VMSA-2021-0020 |
|