VMware vCenter Server Appliance External Control of File Path Denial-of-Service Vulnerability
Vulnerability Details
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of VMware vCenter Server Appliance. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the processing of jsonrpc messages. A crafted request can trigger a file read operation of an endless character stream. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Additional Details
VMware has issued an update to correct this vulnerability. More details can be found at:
https://www.vmware.com/security/advisories/VMSA-2021-0020.html
Disclosure Timeline
- 2021-05-26 - Vulnerability reported to vendor
- 2021-09-22 - Coordinated public release of advisory
Credit
Sergey Gerasimov and George webpentest Noseevich of SolidLab