CVE-2022-22945: OS Command Injection
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-22945?
CVE-2022-22945 refers to a CLI shell injection vulnerability in VMware NSX Edge.
How severe is CVE-2022-22945?
CVE-2022-22945 has a severity score of 7.8 (high).
What is the affected software by CVE-2022-22945?
The affected software by CVE-2022-22945 includes VMware Cloud Foundation versions 3.0 to 3.11 and VMware NSX Data Center up to version 6.4.13 on vSphere.
How can a malicious actor exploit CVE-2022-22945?
A malicious actor with SSH access to an NSX-Edge appliance can exploit CVE-2022-22945 to execute arbitrary commands on the operating system as root.
Where can I find more information about CVE-2022-22945?
You can find more information about CVE-2022-22945 at the official VMware security advisory: https://www.vmware.com/security/advisories/VMSA-2022-0005.html