CISA KEV · catalog date Mar 7, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-21973
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin.
Exploited in the wild (CISA KEV since Mar 7, 2022). NVD reports CVSS 3.1 5.3. EPSS estimates 87.6% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
- State
- PUBLISHED
- Published
- Feb 24, 2021
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAvmwareOriginal evidence ↗
Record text: The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Inspect raw assertion
- Field
container- Value
- The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 87.64% probability · 99.75th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.876400000000; percentile 0.997460000000
FIRST EPSS · score date Aug 27, 2026 · 99.7th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
Outside this view’s verified evidenceReason detail begins outside this selected snapshot; the state remains source-bound.
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
Inspect raw assertion
- Field
container- Value
- The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).
VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability
87.64% probability · 99.75th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.876400000000; percentile 0.997460000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
4 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "4.x before 4.2"}, {"status": "affected", "version": "3.x before 3.10.1.2"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "7.x before 7.0 U1c"}, {"status": "affected", "version": "6.7 before 6.7 U3l"}, {"status": "affected", "version": "6.5 before 6.5 U3n"}]product-29d7e06677052d6292d0854ba656869395ea8e26a3dfe12b466a234813f9d5c3Linked exactInspect raw assertions
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 3.0; through excluding 3.10.1.2
- Match ID
1995769a-1ab9-47fa-966a-8e82d414161e
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 4.0; through excluding 4.2
- Match ID
a608d809-6e65-4228-9207-cb470529c542
product-7b67c9fc3345279c14c2ffdcfdb4cfa4924c4b40fd0abb29ff5aeb5ac44092a7Linked exactInspect raw assertions
cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 36
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5fa81ccd-a05e-498c-820e-21980e92132f
cpe:2.3:a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 25
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23253631-2655-48a8-9b00-cb984232329c
cpe:2.3:a:vmware:vcenter_server:6.7:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
04487105-980a-4943-9360-4442bf0411e6
cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d26534eb-327b-4ed6-a3e1-005552cb1f9d
cpe:2.3:a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 27
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ee4d3e2a-c32d-408f-b811-ef8bc86f0d34
cpe:2.3:a:vmware:vcenter_server:6.7:update3j:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 35
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d06832ce-f946-469d-b495-6735f18d02a0
cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4955663c-1bb6-4f3e-9d4b-362df144b7f1
cpe:2.3:a:vmware:vcenter_server:6.7:update3b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 32
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8af12716-88e2-44b5-acd7-bcbeca130fb8
cpe:2.3:a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
31ca7802-d78d-4bad-a45a-68b601c010c6
cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8678db48-cb98-4e4c-ade6-caba73265fec
cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 38
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fb563627-c9cf-4d8a-b882-9ab65eae9e15
cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
46fc9f34-c8fa-4afe-9f4a-7cf9516bd4d9
cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ce0f8453-3d6c-4f1c-9167-3f02e3d905dc
cpe:2.3:a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
04a60ac7-c2ea-4dbf-9743-54d708584afa
cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e456f84c-a86e-4ea9-9a3e-beea662136e6
cpe:2.3:a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3b98981b-4721-4752-bab4-361db5aeb86f
cpe:2.3:a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 26
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
50c2a9a8-0e66-4702-bcd4-74622108e7a6
cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
23cfe5a5-a166-4fd5-be97-5f16dab1eae0
cpe:2.3:a:vmware:vcenter_server:6.5:update3k:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2f0a79c2-33ae-40c5-a853-770a4c691f29
cpe:2.3:a:vmware:vcenter_server:6.7:update3f:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 33
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3352212c-e820-47b3-bdf5-57018f5b9e81
cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dbd9a341-1fbf-4e04-848b-550deb27261a
cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1f2cb1ff-6118-4875-945d-07baa3a21ffa
cpe:2.3:a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0ead4045-a7f9-464f-abb9-3782941162cc
cpe:2.3:a:vmware:vcenter_server:6.5:e:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
786cdd50-7e18-4437-8db9-2d0adecd436e
cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f1d8161-0e02-45c9-bf61-14799ab65e03
cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cf7ddb0c-3c07-4b5e-8b8a-0542fee72877
cpe:2.3:a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8a91b0c4-f184-459e-afd3-de0e351cc964
cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1aeda28a-5c8e-4e95-a377-3be530dbeab5
cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2c33ce46-f529-4ea9-9344-6ed3bfa7019d
cpe:2.3:a:vmware:vcenter_server:6.7:update3g:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 34
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6436adfd-6b94-4d2a-b09b-ced4ec6ca276
cpe:2.3:a:vmware:vcenter_server:6.5:f:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2ce8dae-0e78-4004-983d-1ecd8855ec33
cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 39
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dca03b2a-48b2-48ad-b8eb-9d7bb2016819
cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1dd16169-a7df-4604-888c-156a60018e32
cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 42
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8725e544-2a94-4829-a683-1ecce57a74a6
cpe:2.3:a:vmware:vcenter_server:6.7:update3a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
24d24e06-eb3f-4f11-849b-e66757b01466
cpe:2.3:a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5241c282-a02b-44b2-b6ca-ba3a99f9737c
cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 41
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d731c1a-9fe5-461c-97e2-6f45e4cbabe1
cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 40
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2392d0f-d7a2-4e01-9212-1ba6c895aebf
cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f72a1e9c-f960-4e8c-a46c-b38209e6349e
cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bddc6510-3116-4578-80c8-8ef044a8370a
cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 37
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0ee83406-a3d9-4f75-a1a6-63831cebeec1
Affected-product evidence
Accepted scope and product mapping
0 canonical links · 0 source-reported links
Applicability remains source-scoped; safety and exposure remain unassessed.
Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NAV:N/AC:L/Au:N/C:P/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NEvidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Affected-product evidence remains source-scoped; canonical linkage is required before applicability scoring.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.