← Back to browse · API

CVE-2022-22948

Severity
MEDIUM
CVSS
6.5
EPSS
0.13825
Risk score
55.84
CISA KEV
Yes
PoC
No
Published
2024-07-17
Modified
2024-07-17
First seen
2026-08-07
Aliases
EUVD-2022-28072, GHSA-MGM9-FFV2-WPC6
Products
VMware:vCenter Server, n/a:VMware vCenter Server and VMware Cloud Foundation VMware vCenter Server (7.0 prior to 7.0 U3d, 6.7 prior to 6.7 U3p and 6.5 prior to 6.5 U3r) and VMware Cloud Foundation (4.x and 3.x prior to 3.11)
Sources
euvd EUVD-2022-28072
cisa.gov CVE-2022-22948

Description

VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.

References