VMware vCenter 低版本存在未授权任意文件读取漏洞,Arbitrary File Read vulnerability in VMware vCenter(Unauthenticated)。
Poc from:https://twitter.com/ptswarm/status/1316016337550938122
:VMware vCenter Server Arbitrary File Read Vulnerability
:info-leak
:critical
:reset-server
:CVE-2021-21986
:
VMware vCenter Server is prone to an arbitrary file read vulnerability while parsing certain crafted HTTP requests. The vulnerability is due to the lack of proper checks on HTTP requests, leading to an exploitable arbitrary file read vulnerability. An attacker could exploit the vulnerability by sending crafted HTTP requests. A successful attack could lead to information disclosure.
:https://github.com/jas502n/Vmware_vCenter/tree/main
如果您认为以上对您有帮助,希望可以点击大拇指点赞,点击关注后续更新。