CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2021-21985

KEV · ransomware Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
Listed
ransomware
Class
other
CWE-918, CWE-20, CWE-470, CWE-918

Description

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

References

Status: profiled · ingested 2026-08-12T06:00:50.000Z