CVE-2022-22948

CVE Published 2022-03-29
Related CWE(s) CWE-276: Incorrect Default Permissions
Related Vendor(s) vmware
Related Product(s) cloud_foundation, vcenter_server
Exploitation Reported (CISA KEV) 2024-07-17
CVSS 3 Base Score 6.5 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2022-22948

Report

Cloaked and Covert: Uncovering UNC3886 Espionage Operations

This article by researchers from Google's Mandiant outlines intrusion activity by UNC3886, a suspected China-nexus cyber espionage group. The ...

Associated CAPEC Patterns

References