CVE-2022-22948

Confirmed PUBLISHED

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative...

VMware · VMware vCenter Server and VMware Cloud Foundation
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.5 Medium

At a Glance

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

cisa nessus_scanner
CVE Published
Mar 29, 2022
Exploitation Reported
Jul 17, 2024
CVSS
6.5 Medium
EPSS
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
vmware
cloud_foundation

4.0 to < 5.0

Affected
vmware
cloud_foundation

3.0 to < 3.11

Affected
vmware
vcenter_server

7.0 to < 7.0_u3d

Affected
vmware
vcenter_server

6.7 to < 6.7_u3p

Affected
vmware
vcenter_server

6.5 to < 6.5_u3r

Affected
n/a
VMware vCenter Server and VMware Cloud Foundation

VMware vCenter Server (7.0 prior to 7.0 U3d, 6.7 prior to 6.7 U3p and 6.5 prior to 6.5 U3r) and VMware Cloud Foundation (4.x and 3.x prior to 3.11)

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.