Aller au contenu

Fiche vulnérabilité

CVE-2021-21982 : faille critique vmware carbon black cloud workload (CVSS 9.1)

Description

VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
1 avr. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • vmware carbon black cloud workload

Références

Rechercher une autre vulnérabilité dans la base CVE