Get a Pentest and security assessment of your IT network.

Cyber Security

Critical RCE Flaws Affect VMware ESXi and vSphere Client Patch Now

Vulnerabilities allow attackers to execute arbitrary commands and take control of affected systems. The vulnerability, tracked as CVE-2021-21972, has a CVSS score of 9.8 out of a maximum of 10, making it critical in severity. The information disclosure issue stems from an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in the vCenter Server plugin. The fix for ESXi OpenSLP comes on the heels of a similar patch (CVE-2020-3992) last November.

Source: https://thehackernews.com/2021/02/critical-rce-flaw-affects-vmware.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security