CVE-2021-22017Disclosure(vmware / vcenter_server)

LOWCVSS 5.3 · MEDIUMCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-01-24. Apply updates per vendor instructions.

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vcenter_server

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
vcenter_server

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-04: 1Technical Details · 2026-02-04: 102-04
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2021-22017 - medium 🚨 vCenter Server - Improper Access Control > Rhttproxy as used in vCenter Server contains a vulnerability due to improper implemen... 👾 https://cloud.projectdiscovery.io/library/CVE-2021-22017 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2021-22017, a medium‑severity improper access control flaw in vCenter Server’s Rhttproxy, without indicating any active exploitation, patch, or PoC.

    01000197
    890 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarevcenter_server6.7--

Explore more