KEVIntel
9.8
CVSS
Critical

CVE-2021-21978

PUBLISHED

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of...

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
VMware
Product
VMware View Planner
Published
Mar 03, 2021
EPSS

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot sensor data — is available programmatically for VM, SOC, and CTI workflows.

Description

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network access to View Planner Harness could upload and execute a specially crafted file leading to remote code execution within the logupload container.

nuclei_scanner metasploit

CVSS scores

CVSS v3.1 9.8 Critical

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0 7.5 High

AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploitation status

Exploited in the wild

Recorded 2025-04-22 00:00:00 UTC · Source

Proof of concept available

Recorded 2021-03-05 03:58:33 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) First 2025-04-22 00:00 UTC

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

vmware_view_planner_4_6_uploadlog_rce

metasploit · Created Unknown

Metasploit module for CVE-2021-21978

skytina/CVE-2021-21978

github · Created 2021-03-05 08:15:27 UTC · 25 stars

带回显版本的漏洞利用脚本

me1ons/CVE-2021-21978

github · Created 2021-03-05 04:33:19 UTC · 5 stars

CVE-2021-21978 EXP

GreyOrder/CVE-2021-21978

github · Created 2021-03-05 03:58:33 UTC · 23 stars

CVE-2021-21978 exp

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit