Attacker Value
Very High
(1 user assessed)
Exploitability
Very High
(1 user assessed)
User Interaction
None
Privileges Required
High
Attack Vector
Network
0

CVE-2021-21983

Disclosure Date: March 31, 2021
Exploited in the Wild
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.

Add Assessment

2
Ratings
  • Attacker Value
    Very High
  • Exploitability
    Very High
Technical Analysis

Please see CVE-2021-21975’s Rapid7 analysis. CVE-2021-21975 can be chained with CVE-2021-21983 to achieve unauthed RCE.

CVSS V3 Severity and Metrics
Base Score:
6.5 Medium
Impact Score:
5.2
Exploitability Score:
1.2
Vector:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • vmware

Products

  • cloud foundation 3.0,
  • cloud foundation 3.0.1,
  • cloud foundation 3.0.1.1,
  • cloud foundation 3.10,
  • cloud foundation 3.5,
  • cloud foundation 3.5.1,
  • cloud foundation 3.7,
  • cloud foundation 3.7.1,
  • cloud foundation 3.7.2,
  • cloud foundation 3.8,
  • cloud foundation 3.8.1,
  • cloud foundation 3.9,
  • cloud foundation 3.9.1,
  • cloud foundation 4.0,
  • cloud foundation 4.0.1,
  • vrealize operations manager 7.0.0,
  • vrealize operations manager 7.5.0,
  • vrealize operations manager 8.0.0,
  • vrealize operations manager 8.0.1,
  • vrealize operations manager 8.1.0,
  • vrealize operations manager 8.1.1,
  • vrealize operations manager 8.2.0,
  • vrealize operations manager 8.3.0,
  • vrealize suite lifecycle manager 8.0,
  • vrealize suite lifecycle manager 8.0.1,
  • vrealize suite lifecycle manager 8.1,
  • vrealize suite lifecycle manager 8.2

Exploited in the Wild

Reported by:

Additional Info

Technical Analysis