VMware vSphere Client是美国威睿(VMware)公司的一个应用软件。提供虚拟化管理。 VMware vSphere Client存在路径遍历漏洞,未授权的攻击者可以通过开放443端口的服务器向vCenter Server发送精心构造的请求,从而在目标系统上远程执行恶意代码。以下产品和版本受到影响:vSphere Client 6.5、vSphere Client 6.7、vSphere Client 7.0、VMware Cloud Foundation(vCenter Server)
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | VMware Cloud Foundation | 4.x before 4.2 |
affected |
3.x before 3.10.1.2 |
affected | ||
| n/a | VMware vCenter Server | 7.x before 7.0 U1c |
affected |
6.7 before 6.7 U3l |
affected | ||
6.5 before 6.5 U3n |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | VMware vCenter Server | 7.x before 7.0 U1c | - |
|
| - | VMware Cloud Foundation | 4.x before 4.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | NSE scripts to detect CVE-2020-1350 SIGRED and CVE-2020-0796 SMBGHOST, CVE-2021-21972, proxyshell, CVE-2021-34473 | https://github.com/psc4re/NSE-scripts | POC Details |
| 2 | None | https://github.com/QmF0c3UK/CVE-2021-21972-vCenter-6.5-7.0-RCE-POC | POC Details |
| 3 | CVE-2021-21972 Exploit | https://github.com/NS-Sp4ce/CVE-2021-21972 | POC Details |
| 4 | None | https://github.com/yaunsky/CVE-2021-21972 | POC Details |
| 5 | Proof of Concept Exploit for vCenter CVE-2021-21972 | https://github.com/horizon3ai/CVE-2021-21972 | POC Details |
| 6 | A vulnerability scanner that detects CVE-2021-21972 vulnerabilities. | https://github.com/Osyanina/westone-CVE-2021-21972-scanner | POC Details |
| 7 | None | https://github.com/alt3kx/CVE-2021-21972 | POC Details |
| 8 | CVE-2021-21972 | https://github.com/milo2012/CVE-2021-21972 | POC Details |
| 9 | CVE-2021-21972 vCenter-6.5-7.0 RCE POC | https://github.com/Udyz/CVE-2021-21972 | POC Details |
| 10 | VMware vCenter 未授权RCE(CVE-2021-21972) | https://github.com/conjojo/VMware_vCenter_UNAuthorized_RCE_CVE-2021-21972 | POC Details |
| 11 | None | https://github.com/L-pin/CVE-2021-21972 | POC Details |
| 12 | VMware vCenter Server远程代码执行漏洞 (CVE-2021-21972)批量检测脚本 | https://github.com/B1anda0/CVE-2021-21972 | POC Details |
| 13 | CVE-2021-21972 | https://github.com/renini/CVE-2021-21972 | POC Details |
| 14 | None | https://github.com/stevenp322/cve-2021-21972 | POC Details |
| 15 | Nmap script to check vulnerability CVE-2021-21972 | https://github.com/GuayoyoCyber/CVE-2021-21972 | POC Details |
| 16 | None | https://github.com/JMousqueton/Detect-CVE-2021-21972 | POC Details |
| 17 | VMware vCenter CVE-2021-21972 Tools | https://github.com/robwillisinfo/VMware_vCenter_CVE-2021-21972 | POC Details |
| 18 | 漏洞利用,Vmware vCenter 6.5-7.0 RCE(CVE-2021-21972),上传冰蝎3,getshell | https://github.com/Ma1Dong/vcenter_rce | POC Details |
| 19 | None | https://github.com/d3sh1n/cve-2021-21972 | POC Details |
| 20 | CVE-2021-21972 related vulnerability code | https://github.com/ByZain/CVE-2021-21972 | POC Details |
| 21 | CVE-2021-21972 Unauthorized RCE in VMware vCenter metasploit exploit script | https://github.com/TaroballzChen/CVE-2021-21972 | POC Details |
| 22 | None | https://github.com/password520/CVE-2021-21972 | POC Details |
| 23 | [CVE-2021-21972] VMware vSphere Client Unauthorized File Upload to Remote Code Execution (RCE) | https://github.com/murataydemir/CVE-2021-21972 | POC Details |
| 24 | POC exploit for CVE-2021-21972 | https://github.com/pettyhacks/vSphereyeeter | POC Details |
| 25 | None | https://github.com/haiclover/CVE-2021-21972 | POC Details |
| 26 | CVE-2021-21972 – ᴠᴍᴡᴀʀᴇ ᴄʟɪᴇɴᴛ ᴜɴᴀᴜᴛʜᴏʀɪᴢᴇᴅ ᴄᴏᴅᴇ ɪɴᴊᴇᴄᴛɪᴏɴ (ʀᴄᴇ) | https://github.com/orangmuda/CVE-2021-21972 | POC Details |
| 27 | None | https://github.com/user16-et/cve-2021-21972_PoC | POC Details |
| 28 | None | https://github.com/haidv35/CVE-2021-21972 | POC Details |
| 29 | None | https://github.com/ZTK-009/CVE-2021-21972 | POC Details |
| 30 | CVE-2021-21972 vCenter-6.5-7.0 RCE POC | https://github.com/TAI-REx/CVE-2021-21972 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-11987 | Apache Batik 代码问题漏洞 | |
| CVE-2021-27645 | GNU C Library和glibc 资源管理错误漏洞 | |
| CVE-2020-12702 | eWeLink mobile application 加密问题漏洞 | |
| CVE-2021-3355 | LightCMS v跨站脚本漏洞 | |
| CVE-2020-28599 | Torsten Paul Openscad 缓冲区错误漏洞 | |
| CVE-2021-22667 | Advantech BB-ESWGP506-2SFP-T 信任管理问题漏洞 | |
| CVE-2021-21973 | VMware vCenter Server 代码问题漏洞 | |
| CVE-2021-21974 | 威睿 VMware ESXi 缓冲区错误漏洞 | |
| CVE-2020-11988 | Apache XmlGraphics Commons 代码问题漏洞 |
No comments yet