CVE-2021-22017

MEDIUM(5.3)KEVElevated Risk

VMware vCenter Server Improper Access Control

Description

CVE-2021-22017 is a medium-severity improper access control vulnerability in VMware vCenter Server. The Rhttproxy component used in vCenter Server contains a flaw due to improper implementation of URI normalization, which allows a malicious actor with network access to port 443 to bypass the proxy and access internal endpoints. This access control vulnerability in VMware vCenter Server can expose internal services that are not intended to be directly accessible. CISA has added CVE-2021-22017 to its Known Exploited Vulnerabilities catalog, and with an EPSS score of 74.08% (98.82nd percentile), the likelihood of exploitation is very high.

KEV Information

Vendor
VMware
Product
vCenter Server
Date Added
January 10, 2022
Due Date
January 24, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4

Affected Products

VendorProductVersion
vmwarevcenter server6.7

Multiple CVSS Assessments

Source: [email protected](Primary)
5.3
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
5.3
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

Weakness Type

Improper Access Control

CVE-2021-22017 involves an improper access control weakness in VMware vCenter Server’s Rhttproxy component. The URI normalization logic fails to properly validate and canonicalize request paths, allowing attackers to craft specially formed URIs that bypass the reverse proxy’s access control mechanisms and reach internal endpoints that should not be directly accessible.

Learn more: CWE-284 — Improper Access Control

Impact Analysis

CVE-2021-22017 carries a CVSS 3.1 score of 5.3 (MEDIUM), reflecting a more limited but still significant security impact. The vulnerability is remotely exploitable over the network with low attack complexity, requires no authentication, and needs no user interaction. Confidentiality (Low): attackers can access some internal endpoints and information that should be restricted by the proxy, though the exposure is limited in scope. Integrity and Availability are not directly impacted according to the CVSS metrics. However, the EPSS score of 74.08% (98.82nd percentile) indicates a very high probability of active exploitation, and the proxy bypass may serve as a stepping stone for deeper attacks when chained with other vCenter Server vulnerabilities. The short CISA remediation deadline of 2022-01-24 (only 14 days) underscores the urgency despite the medium CVSS rating.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2021-22017 in the wild by including it in the Known Exploited Vulnerabilities catalog, with an aggressive remediation deadline of 2022-01-24. The EPSS score of 74.08% (98.82nd percentile) indicates a very high probability of exploitation activity. While no publicly tagged exploit code appears in the NVD references, the VMware advisory VMSA-2021-0020 documents this vulnerability alongside several other critical vCenter Server flaws, suggesting that this URI normalization bypass is often used as part of a broader attack chain against vCenter Server infrastructure.

Remediation

  1. Apply VMware patches immediately as required by CISA KEV: follow the vendor instructions in VMSA-2021-0020 to update VMware vCenter Server 6.7 to the patched version.
  2. Restrict network access to vCenter Server port 443 using firewall rules, allowing connections only from trusted management networks and administrative workstations.
  3. Implement network segmentation to isolate vCenter Server instances from general network traffic, placing them in dedicated management VLANs with strict access controls.
  4. Monitor access logs for unusual URI patterns targeting the Rhttproxy component, particularly requests with path traversal sequences, double encoding, or other URI normalization bypass attempts.
  5. Audit vCenter Server exposure to ensure internal endpoints are not accessible from untrusted networks, and consider deploying a Web Application Firewall (WAF) with URI normalization rules as an additional layer of defense.

Technical Details

CVE-2021-22017 targets the Rhttproxy reverse proxy component in VMware vCenter Server 6.7. The vulnerability arises from improper implementation of URI normalization, a common source of access control bypasses in web applications and reverse proxies. When processing incoming requests on port 443, Rhttproxy fails to properly canonicalize URIs before applying access control rules, allowing attackers to craft specially formed request paths that bypass the proxy’s routing restrictions. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N confirms that the attack is network-based, requires no privileges or user interaction, and primarily impacts confidentiality at a low level by exposing internal endpoints. While the direct impact is limited to information disclosure, the ability to bypass the proxy layer in a critical infrastructure management platform like vCenter Server represents a significant security concern, especially when combined with other vulnerabilities disclosed in the same advisory.

Frequently Asked Questions

Is CVE-2021-22017 being actively exploited?

Yes. CVE-2021-22017 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 74.08% (98.82nd percentile) indicates a very high probability of exploitation. There is no known association with ransomware campaigns at this time.

What products are affected by CVE-2021-22017?

CVE-2021-22017 affects VMware vCenter Server version 6.7. The vulnerability is in the Rhttproxy reverse proxy component, which handles incoming HTTPS connections on port 443.

How do I fix CVE-2021-22017?

Apply the patches documented in VMware advisory VMSA-2021-0020 for vCenter Server 6.7. Additionally, restrict network access to vCenter Server port 443 to trusted management networks only, and monitor access logs for suspicious URI patterns that may indicate exploitation attempts.

How severe is CVE-2021-22017?

CVE-2021-22017 has a CVSS 3.1 score of 5.3 (MEDIUM). While the direct impact is limited to accessing internal endpoints via proxy bypass, its confirmed active exploitation and very high EPSS score (98.82nd percentile) indicate that it is actively targeted. The short CISA remediation deadline of just 14 days further emphasizes its urgency.

CVSS Score

5.3
MEDIUM(5.3)

EPSS Score

EPSS Score49.18%
EPSS Percentile98.8%

Dates

PublishedSeptember 23, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.