CVE Database
/

CVE-2021-21974

Back to search

CVE-2021-21974

Published: Feb 24, 2021

Modified: Jun 2, 2026

PUBLISHED

Description

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

VendorProductVersions

n/a

VMware ESXi

affected
7.0 before ESXi70U1c-17325551
affected
6.7 before ESXi670-202102401-SG
affected
6.5 before ESXi650-202102101-SG

n/a

VMware Cloud Foundation

affected
4.x before 4.2 and 3.x

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now