Critical severity9.8NVD Advisory· Published Jun 23, 2021· Updated Jun 17, 2026
CVE-2021-21998
CVE-2021-21998
Description
VMware Carbon Black App Control 8.0, 8.1, 8.5 prior to 8.5.8, and 8.6 prior to 8.6.2 has an authentication bypass. A malicious actor with network access to the VMware Carbon Black App Control management server might be able to obtain administrative access to the product without the need to authenticate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:*range: >=8.5,<8.5.8
- cpe:2.3:a:vmware:carbon_black_app_control:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:vmware:carbon_black_app_control:8.1:*:*:*:*:*:*:*
- (no CPE)range: <8.5.8, <8.6.2
- VMware/Carbon Black App Controldescription
Patches
Vulnerability mechanics
References
1- www.vmware.com/security/advisories/VMSA-2021-0012.htmlnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.