Unrated severityNVD Advisory· Published Feb 24, 2021· Updated Aug 3, 2024
CVE-2021-21974
CVE-2021-21974
Description
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.
Affected products
1- Range: 7.0 before ESXi70U1c-17325551
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- packetstormsecurity.com/files/162957/VMware-ESXi-OpenSLP-Heap-Overflow.htmlmitrex_refsource_MISC
- www.vmware.com/security/advisories/VMSA-2021-0002.htmlmitrex_refsource_CONFIRM
- www.zerodayinitiative.com/advisories/ZDI-21-250/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.