Cyber Resilience

CVE-2021-22017

Vmware Vcenter Server 6.7

CISA KEVActive ExploitationEUVD Exploited
Published
23 September 2021
Modified
30 October 2025
KEV Added
10 January 2022
Patch / advisory
CVSS Score v3.1 5.3
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score 0.49 99th percentile
Risk Priority 75 floored blend · peak EPSS

Summary

CVE-2021-22017 is a medium-severity an unspecified weakness vulnerability in Vmware Vcenter Server. Its CVSS base score is 5.3 (Medium).

Operationally, ranked in the top 1% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. The affected component is the reverse proxy functionality within VMware vCenter Server, which listens on port 443. The issue received a CVSS v3.1 score of 5.3 and is tracked under NVD-CWE-noinfo.

A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass the proxy, leading to internal endpoints being accessed. The attack requires no authentication or user interaction and results in limited disclosure of information from otherwise protected resources.

The vulnerability is referenced in VMware security advisory VMSA-2021-0020 and appears in the CISA Known Exploited Vulnerabilities catalog, indicating confirmed real-world exploitation activity.

EU & UK References

Vulnerability Data

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being…

more

accessed.

CWE(s)
KEV Date Added
10 January 2022

Related Threats

CVEs Like This One

CVE-2020-3952Same product: Vmware Vcenter Serverboth on KEV
CVE-2023-34048Same product: Vmware Vcenter Serverboth on KEV
CVE-2023-34056Same product: Vmware Vcenter Server
CVE-2023-20896Same product: Vmware Vcenter Server
CVE-2023-20892Same product: Vmware Vcenter Server
CVE-2022-22948Same product: Vmware Vcenter Serverboth on KEV
CVE-2024-38813Same product: Vmware Vcenter Serverboth on KEV
CVE-2021-21972Same product: Vmware Vcenter Serverboth on KEV
CVE-2021-21973Same product: Vmware Vcenter Serverboth on KEV
CVE-2024-38812Same product: Vmware Vcenter Serverboth on KEV

Affected Assets

vmware
vcenter server
6.7

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References