CVE-2021-22054
KEV
🔴 Łataj teraz
Podatność SSRF w VMware Workspace ONE UEM umożliwia dostęp do wrażliwych danych bez uwierzytelnienia.
CVSS
7.5
EPSS
99.7%
Exploit
weaponized
Vendor
vmware
Opis źródłowy (NVD)
VMware Workspace ONE UEM console 20.0.8 prior to 20.0.8.37, 20.11.0 prior to 20.11.0.40, 21.2.0 prior to 21.2.0.27, and 21.5.0 prior to 21.5.0.37 contain an SSRF vulnerability. This issue may allow a malicious actor with network access to UEM to send their requests without authentication and to gain access to sensitive information.
ssrf
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 99.7% |
| Opublikowano (NVD) | 2021-12-17 17:15:12 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 19:17:13 UTC |
Referencje
- https://www.vmware.com/security/advisories/VMSA-2021-0029.html ([email protected]) [Patch, Vendor Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22054 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]
- https://www.greynoise.io/blog/new-ssrf-exploitation-surge (134c704f-9b21-4f2e-91b3-4a467353bcc0) [Third Party Advisory]