VMware vCenter Server CVE-2021-21972 Remote Code Execution Vulnerability: What You Need to Know

VMware vCenter Server CVE-2021-21972 Remote Code Execution Vulnerability: What You Need to Know https://ift.tt/3dKcglW This blog post was co-authored by Bob Rudis and Caitlin Condon. What’s up? On Feb. 23, 2021, VMware published an advisory (VMSA-2021-0002) describing three weaknesses affecting VMware ESXi, VMware vCenter Server, and VMware Cloud Foundation. Before digging into the individual vulnerabilities, […]

FortiGate Securing Remote Administration

FortiGate Securing Remote Administration https://ift.tt/2YNoAZR KB ID 0001734 Problem When considering Securing FortiGate  remote administration, I’ve written about changing the https management port to something other than TCP 443 before, I suppose that’s security by obfuscation (though even a script kiddy with one hours experience, will be able to spot an html responses).  Typically with […]

VMSA-2021-0002 updates for VMware ESXi and vCenter address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974)

VMSA-2021-0002 updates for VMware ESXi and vCenter address multiple security vulnerabilities (CVE-2021-21972, CVE-2021-21973, CVE-2021-21974) https://ift.tt/3dHq1S8 Yesterday, VMware released an update that addresses three vulnerabilities in its ESXi, vCenter Server and Cloud Foundation products: A remote code execution vulnerability in the vSphere Client (CVE-2021-21972) An SSRF vulnerability in the vSphere Client (CVE-2021-21973) An ESXi OpenSLP heap-overflow […]