CVE-2021-22055
CVE-2021-22055 is a medium-severity vulnerability in Vmware Photon Os with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-74.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v2: 5.0
- EPSS exploit prediction: 1% (61st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-74
- Affected product: Vmware Photon Os
- Published:
- Last modified:
Description
The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries.
Frequently asked questions
- What is CVE-2021-22055?
- The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries.
- How severe is CVE-2021-22055?
- CVE-2021-22055 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2021-22055 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (61st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-22055?
- CVE-2021-22055 affects Vmware Photon Os. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-22055?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-22055 published?
- CVE-2021-22055 was published on 2022-04-11 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:o:vmware:photon_os:*:*:*:*:*:*:*:*
More vulnerabilities in Vmware Photon Os
- CVE-2016-5333 — Critical (CVSS 9.8): VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote…
- CVE-2020-10713 — High (CVSS 8.2): A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB…
- CVE-2022-22942 — High (CVSS 7.8): The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to…
All CVEs affecting Vmware Photon Os →
Other CWE-74 (Improper Neutralization of Special Elements (Injection)) vulnerabilities
- CVE-2026-105135 — Critical (CVSS 10.0): A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the…
- CVE-2026-61732 — Critical (CVSS 10.0): Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output…
- CVE-2026-94097 — Critical (CVSS 10.0): A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file…
- CVE-2026-20130 — Critical (CVSS 10.0): As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine…
- CVE-2026-82971 — Critical (CVSS 10.0): A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file…
- CVE-2026-54159 — Critical (CVSS 10.0): PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the…
Browse all CWE-74 (Improper Neutralization of Special Elements (Injection)) vulnerabilities →