VMware vCenter Server File Upload Vulnerability
n/a — VMware vCenter Server, VMware Cloud Foundation
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- Sep 23, 2021
- Modified
- Jun 17, 2026
- Added to KEV
- Nov 3, 2021
- Federal patch due
- Nov 17, 2021
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2021-22005, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- Schira4396/VcenterKiller★ 1483
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接
updated Aug 30, 2026
- shmilylty/cve-2021-22005-exp★ 194
updated Sep 2, 2026
- rwincey/CVE-2021-22005★ 37
updated Mar 9, 2025
- TaroballzChen/CVE-2021-22005-metasploit★ 22
the metasploit script(POC/EXP) about CVE-2021-22005 VMware vCenter Server contains an arbitrary file upload vulnerability
updated Jan 13, 2026
- Jun-5heng/CVE-2021-22005★ 21
VMware vCenter Server任意文件上传漏洞 / Code By:Jun_sheng
updated Dec 12, 2025
- 5gstudent/CVE-2021-22005-★ 13
CVE-2021-22005批量验证python脚本
updated Nov 14, 2025
- 1ZRR4H/CVE-2021-22005★ 8
updated Dec 29, 2023
- CrackerCat/CVE-2021-22006★ 3
CVE-2021-22005 - VMWare vCenter Server File Upload to RCE
updated Jun 8, 2025
References
How this class of flaw gets exploited
Frequently asked questions
What is CVE-2021-22005?
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.
How severe is CVE-2021-22005?
CVE-2021-22005 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2021-22005 actively exploited in the wild?
Yes. CVE-2021-22005 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 3, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2021-22005?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2021-22005?
Yes - a public Nuclei template referencing CVE-2021-22005 exist in public repositories we checked. We also found 8 public GitHub repositories referencing this CVE.
What type of vulnerability is CVE-2021-22005?
CVE-2021-22005 is classified under CWE-22 (CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
Cross-checked against
Impactr finds and proves whether CVE-2021-22005 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist