Security firm Positive Technologies says more than 6,000 VMware vCenter devices worldwide that are accessible via the internet contain a critical remote code execution vulnerability. The vulnerability, CVE-2021-21972, carries a CVSS v3 score of 9.8, which makes it extremely critical. If exploited, it enables hackers to execute arbitrary commands to compromise the vCenter Server and potentially gain access to sensitive data. The flaw is found in vSphere Client (HTML5), a plugin of the. plugin of. VMware has issued recommendations for patching the flaw.”]
Source: https://www.bankinfosecurity.com/6000-vmware-vcenter-devices-vulnerable-to-remote-attacks-a-16066