
Nmap स्क्रिप्ट जो uploadova एंडपॉइंट की प्रोबिंग करके और असुरक्षित प्रतिक्रिया की जाँच करके VMware vCenter Server CVE-2021-21972 RCE भेद्यता का पता लगाती है।
VMware vCenter Server CVE-2021-21972 रिमोट कोड निष्पादन भेद्यता
यह स्क्रिप्ट निम्नलिखित PATH के आधार पर CVE-2021-21972 की उपस्थिति की जाँच करती है "/ui/vropspluginui/rest/services/uploadova" POST अनुरोध के माध्यम से और प्रतिक्रिया निकाय (500) में "uploadFile" शब्दों को देखकर, इसका मतलब है कि vCenter बिना किसी प्रतिबंध के POST के माध्यम से फ़ाइलें स्वीकार करने के लिए उपलब्ध है
मैन्युअल जाँच:
# curl -i -s -k -X $'GET' -H $'Host: <target>' -H $'User-Agent: alex666' $'https://<target>/ui/vropspluginui/rest/services/getstatus'
# curl -i -s -k -X $'GET' -H $'Host: <target>' -H $'User-Agent: alex666'$'https://<target>/ui/vropspluginui/rest/services/uploadova'
# curl -i -s -k -X $'POST' -H $'Host: <target>' -H $'User-Agent: alex666' -H $'Content-Type: application/x-www-form-urlencoded' -H $'Content-Length: 0' $'https://<target>/ui/vropspluginui/rest/services/uploadova'
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972
https://www.vmware.com/security/advisories/VMSA-2021-0002.html
nmap -p443 --script CVE-2021-21972.nse <target>
---
-- @usage
-- nmap -p443 --script CVE-2021-21972.nse <target>
-- @output
-- PORT STATE SERVICE
-- 443/tcp open https
-- | CVE-2021-21972:
-- | VULNERABLE:
-- | vCenter 6.5-7.0 RCE
-- | State: VULNERABLE (Exploitable)
-- | IDs: CVE:CVE-2021-21972
-- | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
-- | A malicious actor with network access to port 443 may exploit this issue to execute commands with
-- | unrestricted privileges on the underlying operating system that hosts vCenter Server.
-- | Disclosure date: 2021-02-23
-- | References:
-- |_ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21972

Alex Hernandez उर्फ (@_alt3kx_)