CVE-2021-22005
KEV RANSOMWARECRITICAL 9.8EPSS 100.0%
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-22
- Published
- 2021-09-23
- Updated
- 2025-10-21
Proof-of-concept exploits (20)
- http://packetstormsecurity.com/files/164439/VMware-vCenter-Server-Analytics-CEIP-Service-…
- 1ZRR4H/CVE-2021-220058★ · 2021-09-23
- 24-2021/EXP-POC26★ · 2023-01-11
- 5gstudent/CVE-2021-22005-13★ · 2021-09-25
- InventorMAO/cve-2021-220050★ · 2022-06-21
- Jun-5heng/CVE-2021-2200521★ · 2022-07-08
- RedTeamExp/CVE-2021-22005_PoC1★ · 2021-09-27
- TaroballzChen/CVE-2021-22005-metasploit22★ · 2021-10-02
- TiagoSergio/CVE-2021-220052★ · 2021-10-24
- Vulnmachines/VmWare-vCenter-vulnerability8★ · 2022-07-26
- chaosec2021/EXP-POC26★ · 2023-01-11
- mamba-2021/EXP-POC26★ · 2023-01-11
- rwincey/CVE-2021-2200537★ · 2021-09-28
- shmilylty/cve-2021-22005-exp195★ · 2021-12-22
- tiagob0b/CVE-2021-220052★ · 2021-10-24
- timb-machine-mirrors/CVE-2021-220050★ · 2022-01-05
- timb-machine-mirrors/testanull-CVE-2021-22005.py0★ · 2022-01-05
- vikerup/Get-vSphereVersion2★ · 2023-04-27
- viksafe/Get-vSphereVersion2★ · 2023-04-27
- zidanfanshao/vcenter_tools70★ · 2024-11-17