VMware vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the VMware vSAN health check plug-in. A malicious actor with network access to port 443 might exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. The Common Vulnerabilities and Exposures project (
cve.mitre.org) has assigned the identifier
CVE-2021-21985 to this issue. For more information, see VMware Security Advisory
VMSA-2021-0010.