6.5
CVSSv3

CVE-2022-22948

Published: 29/03/2022 Updated: 08/04/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vmware cloud foundation

vmware cloud foundation 3.11

vmware vcenter server 6.5

vmware vcenter server 6.7

vmware vcenter server 7.0

Vendor Advisories

Sign up for Security Advisories Stay up to date on the latest VMware Security advisories and updates ...

Github Repositories

Scanner for CVE-2022-22948 an Information Disclosure in VMWare vCenter

CVE-2022-22948 Information Disclosure in VMWare vCenter Pentera’s research group discovered a vulnerability in VMWare’s vCenter Server program affecting VMWare’s software installed in 500,000 organizations worldwide responsible to manage their most critical systems Our findings were proactively reported to VMWare and were released under CVE-2022-22948 Patch a