← العودة للجدول
CVE-2021-22002
CVE-2021-22002 — VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and dia
📅 2021-08-31
🔴 Critical 🔥 No NVD Exploit VMware CVSS 9.8 🎯 EPSS 0.37%

📋 الوصف الكامل

VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.

💻 الأنظمة المتأثرة

VMware

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2021-22002

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2021-22002 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←