First published: Wed Feb 16 2022(Updated: )
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Cloud Foundation | >=3.0<=3.11 | |
Vmware Nsx Data Center | <6.4.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22945 refers to a CLI shell injection vulnerability in VMware NSX Edge.
CVE-2022-22945 has a severity score of 7.8 (high).
The affected software by CVE-2022-22945 includes VMware Cloud Foundation versions 3.0 to 3.11 and VMware NSX Data Center up to version 6.4.13 on vSphere.
A malicious actor with SSH access to an NSX-Edge appliance can exploit CVE-2022-22945 to execute arbitrary commands on the operating system as root.
You can find more information about CVE-2022-22945 at the official VMware security advisory: https://www.vmware.com/security/advisories/VMSA-2022-0005.html