Lucene search

K
prionPRIOn knowledge basePRION:CVE-2021-21985
HistoryMay 26, 2021 - 3:15 p.m.

Remote code execution

2021-05-2615:15:00
PRIOn knowledge base
www.prio-n.com
11

9.8 High

AI Score

Confidence

High

0.974 High

EPSS

Percentile

99.9%

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.