445
VMScore

CVE-2021-22003

Published: 31/08/2021 Updated: 09/09/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware identity_manager 3.3.2

vmware identity_manager 3.3.3

vmware identity_manager 3.3.4

vmware identity_manager 3.3.5

vmware workspace_one_access 20.01

vmware workspace_one_access 20.10

vmware workspace_one_access 20.10.01

vmware cloud foundation 4.0

vmware cloud foundation 4.0.1

vmware cloud foundation 4.1

vmware cloud foundation 4.1.0.1

vmware cloud foundation 4.2.1

vmware vrealize suite lifecycle manager 8.0

vmware vrealize suite lifecycle manager 8.0.1

vmware vrealize suite lifecycle manager 8.1

vmware vrealize suite lifecycle manager 8.2

Vendor Advisories

Sign up for Security Advisories Stay up to date on the latest VMware Security advisories and updates ...