Rewterz
Rewterz Threat Advisory – ICS: Rockwell Automation FactoryTalk AssetCentre Multiple Vulnerabilities
April 2, 2021
Rewterz
Rewterz Threat Alert – IcedID banking Trojan – IOCs
April 2, 2021

Rewterz Threat Advisory – CVE-2021-21982 – VMware Carbon Black Cloud Workload appliance security bypass

Severity

High

Analysis Summary

CVE-2021-21982

VMware Carbon Black Cloud Workload appliance could allow a remote attacker to bypass security restrictions, caused by the manipulation of a URL on the administrative interface. An attacker could exploit this vulnerability to bypass the authentication process.

Impact

Security bypass

Affected Vendors

VMware

Affected Products

VMware Carbon Black Cloud Workload appliance 1.0.1

Remediation

Refer to VMware Security advisory for patch, upgrade or suggested workaround information.

VMware Security Advisory VMSA-2021-0005