← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-26987

Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12.2 contain vulnerable versions of SpringBoot Framework.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:2.44%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
vmware spring_boot all
netapp element_plug-in_for_vcenter_server all
netapp management_services_for_element_software_and_netapp_hci all
netapp solidfire_\&_hci_management_node all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.440%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityNetApp, Inc. · Vendor · USA
Reserved2021-02-09T00:00:00
Published2021-03-15T21:28:13
Last Updated2024-08-03T20:40:45

LINK COPIED TO CLIPBOARD