Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21978

Опубликовано: 03 мар. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Критический

Описание

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vmware:view_planner:*:*:*:*:*:*:*:*
Версия от 4.0 (включая) до 4.6 (исключая)
cpe:2.3:a:vmware:view_planner:4.6:-:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.90903
Критический

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

CVSS3: 9.8
fstec
почти 5 лет назад

Уязвимость веб-приложения logupload программного средства моделирования нагрузочного тестирования инфраструктуры виртуальных ПК VMware View Planner, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.90903
Критический

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20