
Il 21 settembre 2021, VMware ha pubblicato un advisory di sicurezza in cui sono state divulgate 19 vulnerabilità in vCenter Server, con punteggi CVSSv3 compresi tra 4.3 e 9.8.
Tra queste, la vulnerabilità più grave è quella di caricamento arbitrario di file in vCenter Server (CVE-2021-22005), situata nel servizio di analisi di vCenter Server, con punteggio CVSSv3 di 9.8. Un attaccante in grado di raggiungere via rete la porta 443 di vCenter Server può eseguire codice in remoto su vCenter Server caricando un file malevolo. La vulnerabilità può essere sfruttata in remoto senza autenticazione, presenta una bassa complessità di attacco e non richiede interazione con l'utente.
Le versioni Windows di vCenter 6.7 non sono interessate.
https://testbnull.medium.com/quick-note-of-vcenter-rce-cve-2021-22005-4337d5a817ee
Nota: questo exp funziona solo contro vCenter in versione Linux.
Aiuto
usage: exp [-h] -t TARGET [-s SHELL] [-p PROXY]
optional arguments:
-h, --help show this help message and exit
-t TARGET, --target TARGET
target url(e.g. https://192.168.1.1)
-s SHELL, --shell SHELL
local webshell file path(default cmd.jsp)
-p PROXY, --proxy PROXY
request proxy(e.g. http://127.0.0.1:1080)
Questo exp è stato testato con successo su VMware vCenter Server 7.0.0 build-16323968.
