Junglewise Threat Intelligence

CVE-2022-22948: VMware vCenter Server Incorrect Default File Permissions Vulnerability

CVE-2022-22948 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2024-07-17

Technologies: Broadcom vCenter Server, VMware Cloud Foundation. Vendors: VMware, Broadcom.

Executive brief

VMware vCenter Server contains an information disclosure vulnerability due to improper default file permissions. A malicious actor with non-administrative (privileged) network access can exploit this to gain access to sensitive information.

Affected products

  • VMware vCenter Server 6.5, 6.7, 7.0 before 7.0 U3c
  • VMware Cloud Foundation 3.x before 3.11, 4.x before 4.4.1

Timeline

  • 2022-03-29: disclosed: Initial vendor advisory VMSA-2022-0009 published
  • 2024-07-17: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats