Jul 17, 2021

Improper Authentication CVE-2021-21994

Improper authentication vulnerability found at VMware cloud_foundation and ESXi.


 [*] Searching cve-[['2021-21994']] vulnerability definitions within Kenna.VI+....


[ CVE Description ]
 [*] CVE_ID : CVE-2021-21994
 [_] Desc   : SFCB (Small Footprint CIM Broker) as used in ESXi has an authentication bypass vulnerability. A malicious actor with network access to port 5989 on ESXi may exploit this issue to bypass SFCB authentication by sending a specially crafted request.

 [_] C:2021-01-04 / P:2021-07-13 / L:2021-07-16
 [*] Vuln Risk           : 29.6943
 [*] Exploited [trend]   : 0 [holding]
 [_] Exploit/likehood    : False/0.5843% confidence

 [*] Malware sample : 0
 [*] Exploits/POC   : [0]
 [_] Fixes          : [0]
 [_] Threat Actors  : [0]
 [_] CVSS2 / CVSS3  : [ 6.8 / 9.8 ]

 [_] Vuln Products  : [8]

[ CVE Malware Family Info : None ]

[ High_Profile_Vulnerability ]
 [!!!]   CVE-2021-21994 (29.6943) : []


 ** [5] threads completed [2 tasks] / [2.06 KB] within [2.01 sec].