VYPR
Unrated severityNVD Advisory· Published Aug 31, 2021· Updated Aug 3, 2024

CVE-2021-22003

CVE-2021-22003

Description

VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

VMware Workspace ONE Access and Identity Manager exposed a login interface on port 7443, enabling potential user enumeration or brute-force attacks if lockout policies are weak.

Vulnerability

The affected products, VMware Workspace ONE Access and Identity Manager (and related components such as vRealize Automation), unintentionally provide a login interface on TCP port 7443 [1]. This port is accessible to any network actor who can reach the server. The vulnerability affects all versions prior to the patches released in August 2021, as detailed in VMSA-2021-0016 [1].

Exploitation

A malicious actor with network access to port 7443 can attempt to enumerate valid user accounts or perform password brute-force attacks against the login endpoint [1]. The practical success of such attacks depends on the target environment's account lockout policy and password complexity requirements; if lockout thresholds are high or absent, brute-force attempts become more feasible [1]. No authentication or prior access is required for the attacker to reach the exposed endpoint.

Impact

If an attacker successfully enumerates a valid username or guesses a weak password, they could gain unauthorized access to the Workspace ONE Access or Identity Manager console [1]. This could lead to disclosure of sensitive information or further compromise within the affected VMware deployment. The CVSSv3 base score for this vulnerability is 5.3 (medium), reflecting the limited impact given typical account lockout policies [1].

Mitigation

VMware released fixed versions in August 2021 as part of VMSA-2021-0016 [1]. The advisory provides specific patch information for Workspace ONE Access, Identity Manager, vRealize Automation, and related products. Administrators should immediately apply the recommended patches or follow the workaround guidance in the advisory. No workaround other than restricting network access to port 7443 or upgrading is suggested. VMware has not listed this CVE in the KEV catalog.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.