Critical severity9.8NVD Advisory· Published Mar 15, 2021· Updated Jun 17, 2026
CVE-2021-26987
CVE-2021-26987
Description
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringBoot Framework.
Affected products
6- cpe:2.3:a:netapp:element_plug-in_for_vcenter_server:*:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:management_services_for_element_software_and_netapp_hci:*:*:*:*:*:*:*:*Range: <2.17.56
- cpe:2.3:a:netapp:solidfire_\&_hci_management_node:*:*:*:*:*:*:*:*Range: <=12.2
- VMware/Element Plug-in for vCenter Serverdescription
- Range: <1.3.2
Patches
Vulnerability mechanics
References
1- security.netapp.com/advisory/ntap-20210315-0001/nvdVendor Advisory
News mentions
0No linked articles in our index yet.