Back to search
CVE-2021-21995
Published: Jul 13, 2021
Modified: Aug 3, 2024
PUBLISHED
Description
OpenSLP as used in ESXi has a denial-of-service vulnerability due a heap out-of-bounds read issue. A malicious actor with network access to port 427 on ESXi may be able to trigger a heap out-of-bounds read in OpenSLP service resulting in a denial-of-service condition.
| Vendor | Product | Versions |
|---|---|---|
n/a | VMware ESXi and VMware Cloud Foundation | affected VMware ESXi(7.0 before ESXi70U2-17630552, 6.7 before ESXi670-202103101-SG, 6.5 before ESXi650-202107401-SG) and VMware Cloud Foundation (4.x, 3.x before 3.10.2) |
References
https://www.vmware.com/security/advisories/VMSA-2021-0014.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now