2021-04-01 (Initial Advisory)
VMware Carbon Black Cloud Workload appliance update addresses incorrect URL handling vulnerability (CVE-2021-21982)
1. Impacted Products
VMware Carbon Black Cloud Workload appliance.
A vulnerability in VMware Carbon Black Cloud Workload appliance was privately reported to VMware. An update is available to remediate this vulnerability in the affected versions of the appliance.
3. Advisory Details
A URL on the administrative interface of the VMware Carbon Black Cloud Workload appliance can be manipulated to bypass authentication. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.1.
Known Attack Vectors
A malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance may be able to obtain a valid authentication token, granting access to the administration API of the appliance. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.
To remediate CVE-2021-21982 apply the updates listed in the ‘Fixed Version’ column of the ‘Response Matrix’ below to affected deployments.
VMware best practices recommend implementing network controls to limit access to the local administrative interface of the appliance. Unrestricted network access to this interface is not required for the regular operation of the product.
VMware would like to thank Egor Dimitrenko of Positive Technologies for reporting this issue to us.
VMware Carbon Black Cloud Workload appliance
1.0.1 and prior
Fixed Version(s) and/or Release Noteshttps://docs.vmware.com/en/VMware-Carbon-Black-Cloud-Workload/1.0/rn/cbc-workload-102-release-notes.html Mitre CVE Dictionary Linkshttps://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21982 FIRST CVSSv3 Calculatorhttps://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
5. Change Log
2021-04-01 VMSA-2021-0005Initial security advisory.
E-mail list for product security notifications and announcements:
This Security Advisory is posted to the following lists:
PGP key at:
VMware Security Advisories
VMware Security Response Policy
VMware Lifecycle Support Phases
VMware Security & Compliance Blog
Tweets by VMwareSRC
Copyright 2021 VMware Inc. All rights reserved. VMware Security AdvisoryRead More