CVE-2022-22948: VMware vCenter Server Incorrect Default File Permissions Vulnerability
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
Other sources
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of VMware vCenter Server and Cloud Foundation if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22948?
CVE-2022-22948 has a high severity rating due to its potential for information disclosure by malicious actors.
How do I fix CVE-2022-22948?
To fix CVE-2022-22948, it is recommended to update the VMware vCenter Server to the latest version provided by VMware.
What type of vulnerability is CVE-2022-22948?
CVE-2022-22948 is classified as an information disclosure vulnerability due to improper permissions on files.
Who is affected by CVE-2022-22948?
CVE-2022-22948 affects users of VMware vCenter Server and Cloud Foundation who have non-administrative access.
What could be the consequences of exploiting CVE-2022-22948?
Exploiting CVE-2022-22948 could allow attackers to gain unauthorized access to sensitive information within the vCenter Server.