CVE-2022-22948
בינונית 6.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- VMware vCenter Server Incorrect Default File Permissions Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 14% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-276
מוצרים מושפעים
vmware: cloud foundation; vmware: vcenter server
קישורים
- https://www.vmware.com/security/advisories/VMSA-2022-0009.html PatchVendor Advisory
- https://www.vmware.com/security/advisories/VMSA-2022-0009.html PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource