Vulnerability record · CVE-2021-22017 · published 23 September 2021
CVE-2021-22017: VMware vCenter Server rhttproxy URI normalization bypass
Vmware · Vcenter Server
The rhttproxy component in VMware vCenter Server mishandles URI normalization, allowing a remote attacker to bypass the reverse proxy and reach internal endpoints. Because the proxy is meant to shield internal services, this flaw exposes interfaces that should not be reachable from the network.
Description
Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
high priorityThe flaw is unauthenticated and network-reachable, is listed in CISA KEV as exploited, and has a very high EPSS score, though the CVSS impact is limited to low confidentiality.
What it is
The rhttproxy component in VMware vCenter Server mishandles URI normalization, allowing a remote attacker to bypass the reverse proxy and reach internal endpoints. Because the proxy is meant to shield internal services, this flaw exposes interfaces that should not be reachable from the network.
Impact
An unauthenticated attacker with network access to port 443 can reach internal endpoints behind the proxy, gaining low-level read access to information that would otherwise be restricted.
Attack surface
Reachable over the network on vCenter Server port 443; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-01-10, indicating real-world exploitation; EPSS is 0.49177 (98.8th percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor patch per VMware advisory VMSA-2021-0020.
- Restrict network access to vCenter Server port 443 to trusted management networks only.
- Place vCenter Server behind a properly configured reverse proxy or firewall that normalizes and validates request URIs.
- Monitor for and block requests containing encoded path traversal or unusual URI normalization patterns.
- Verify patched status against the CISA KEV required action and remediate by the due date.
Detection
- Inspect vCenter and reverse proxy logs for requests with encoded characters, double-encoding, or path traversal sequences targeting internal endpoints.
- Alert on access to internal-only vCenter endpoints from unexpected source IPs.
- Correlate port 443 traffic to vCenter with known exploitation patterns for rhttproxy URI normalization bypass.
- Review vCenter audit logs for anomalous requests that bypass normal proxy routing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-22017 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "VMware vCenter Server Improper Access Control". Required action: Apply updates per vendor instructions. Federal deadline 24 January 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2021-0020.html | PatchVendor Advisory |
| https://www.vmware.com/security/advisories/VMSA-2021-0020.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22017 | US Government Resource |
Track CVE-2021-22017 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.