LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-21973: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 21, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-21973 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Mar 21, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

VMware vCenter Server and Cloud Foundation Server contain a SSRF vulnerability due to improper validation of URLs in a vCenter Server plugin. This allows for information disclosure.

CVE-2021-21973 is a server-side request forgery (SSRF) vulnerability in VMware vCenter Server and Cloud Foundation. It stems from improper validation of URLs in a vCenter Server plugin and can allow an attacker to cause information disclosure. Because vCenter is a central management plane for virtual infrastructure, any flaw that lets an attacker influence outbound requests from it deserves prompt attention from IT and security teams.

Public detail is limited to the CISA description and the stated weakness classes. Confirm exact affected builds, fixed versions, and any prerequisites against the vendor advisory before acting.

How it works

The vulnerability is classified under CWE-918 (Server-Side Request Forgery) and CWE-20 (Improper Input Validation). In an SSRF flaw of this type, the application accepts a URL or similar reference supplied by a user or another component and then makes a server-side request to that destination without adequate checks. Because the request originates from the trusted vCenter host, it can reach internal services, metadata endpoints, or other network locations that an external attacker could not contact directly.

According to the CISA summary, the root cause is improper validation of URLs inside a vCenter Server plugin. Successful abuse can lead to information disclosure—for example, by inducing the server to fetch content from internal resources and return or leak portions of the response. Specific exploit mechanics, required privileges, and exact request formats are not provided in the given facts; treat any public proof-of-concept claims cautiously and verify them against the vendor advisory.

Am I affected? How to find it in your systems

VMware vCenter Server is commonly deployed as the management component for vSphere environments, either as a Windows installation (older deployments) or as the vCenter Server Appliance (VCSA). VMware Cloud Foundation includes vCenter as part of its stack. Inventory every vCenter instance and Cloud Foundation management domain in your estate, including lab, DR, and edge sites.

For signs of exploitation, examine vCenter and reverse-proxy logs for unusual outbound HTTP/HTTPS requests originating from the vCenter host, especially to internal IP ranges, link-local addresses, or unexpected external destinations. Correlate with authentication anomalies and plugin-related errors. Specific log signatures are not supplied in the given facts, so baseline normal plugin traffic and investigate deviations.

How to remediate

Patching is the primary remediation. Apply the updates published by VMware for vCenter Server and Cloud Foundation exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls:

These measures do not eliminate the vulnerability; they only lower the likelihood and impact of exploitation until the patch is applied.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and data exposure. The given facts do not document ransomware use for this CVE, but information disclosure via SSRF can still reveal credentials, internal topology, or other sensitive data that enables further compromise. If you suspect exploitation, preserve logs, isolate affected systems as appropriate, rotate any credentials that may have been reachable from vCenter, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedVMware · vCenter Server and Cloud Foundation
WeaknessCWE-20
Added to CISA KEVMar 7, 2022
Federal patch deadlineMar 21, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities