CVE-2022-22948
KEVmassInformation Disclosure via Incorrect File Permissions in VMware vCenter Server
CISA: VMware vCenter Server Incorrect Default File Permissions Vulnerability
VMware vCenter Server ships certain files with incorrectly permissive default file permissions, creating an information disclosure vulnerability (CWE-276). A malicious actor with non-administrative (low-privileged) network access to the vCenter Server can exploit the misconfigured permissions to read sensitive information; per the CVSS vector there is confidentiality impact only, with no integrity or availability effect. Any organization running VMware vCenter Server, or VMware Cloud Foundation whose vCenter Server component is affected, is exposed to the flaw. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-07-17, indicating exploitation in the wild, and EPSS currently assigns a 13.3% probability of exploitation within 30 days (96th percentile); no public proof-of-concept is known.
What to do: Upgrade vCenter Server and the vCenter Server component of Cloud Foundation to the fixed releases cited in VMware's advisory for CVE-2022-22948, per the CISA KEV required action (or discontinue use if patching is unavailable). Given the KEV listing and headlines describing stealthy VMware-focused activity by UNC3886, prioritize internet-exposed and high-value vCenter deployments, review which non-administrative accounts can reach the vCenter appliance, and monitor those accounts and vCenter logs for signs of unauthorized file access.
| VMware vCenter Server | — |
| VMware Cloud Foundation (vCenter Server component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
- Affected
- VMware vCenter Server
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- cloud foundation, vcenter server
- Weakness
- CWE-276
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N