VMware vCenter Server File Upload CVE-2021-22005
Detects exploitation attempts using file upload vulnerability CVE-2021-22005 in the VMWare vCenter Server.
Sigma rule (View on GitHub)
1title: VMware vCenter Server File Upload CVE-2021-22005
2id: b014ea07-8ea0-4859-b517-50a4e5b7ecec
3status: test
4description: Detects exploitation attempts using file upload vulnerability CVE-2021-22005 in the VMWare vCenter Server.
5references:
6 - https://kb.vmware.com/s/article/85717
7 - https://www.tenable.com/blog/cve-2021-22005-critical-file-upload-vulnerability-in-vmware-vcenter-server
8author: Sittikorn S
9date: 2021-09-24
10modified: 2023-01-02
11tags:
12 - attack.initial-access
13 - attack.t1190
14 - cve.2021-22005
15 - detection.emerging-threats
16logsource:
17 category: webserver
18detection:
19 selection:
20 cs-method: 'POST'
21 cs-uri-query|contains: '/analytics/telemetry/ph/api/hyper/send?'
22 condition: selection
23falsepositives:
24 - Vulnerability Scanning
25level: high
References
Related rules
- ADSelfService Exploitation
- Apache Spark Shell Command Injection - Weblogs
- Arcadyan Router Exploitations
- Atlassian Bitbucket Command Injection Via Archive API
- CVE-2010-5278 Exploitation Attempt