Servers Australia Maintenance - Emergency vCenter CVE Fix - 26 May 2021

  • Wednesday, 26th May, 2021
  • 07:16am

Emergency vCenter CVE Fix

Upcoming scheduled maintenance notice

Important: No services will be affected during this maintenance - only vCenter UI and VM consoles will become unavailable for a short period.

Description:
Vulnerabilities in plugins that ship with vCenter Server have been disclosed by VMware. While there is no released attack method, Servers Australia would still like to apply the fix as soon as possible. These vulnerabilities and their impact on VMware products are documented in the following VMware Security Advisories (VMSAs).

CVE-2021-21972 - VMSA-2021-0002 (vRealize Operations Manager Plugin)
CVE-2021-21985 - VMSA-2021-0010 (Virtual SAN Health Check Plugin)
CVE-2021-21986 - VMSA-2021-0010 (Virtual SAN Health Check, Site Recovery, vSphere Lifecycle Manager, and VMware Cloud Director Availability Plugins)


Resolution:
VMware has released a workaround which requires the vCenter services to be restarted.

Servers Australia engineers will be applying this workaround to all affected vCenter infrastructure at the times mentioned above.

As such you will notice a short period of time during the maintenance that the vCenter UI will become unavailable.

During the maintenance, Cloud Server and VPS consoles will also be unavailable.

You can see the full details from VMWare here: https://kb.vmware.com/s/article/83829

Start time

 

May 26, 23:00 AEST


Estimated duration

1 hour


Components affected

Services - Cloud Servers

 

Services - Private Cloud
« Back