CVE-2022-22951: Command Injection
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22951.
What is the severity of CVE-2022-22951?
The severity of CVE-2022-22951 is critical with a CVSS score of 9.1.
What is the affected software version range for CVE-2022-22951?
The affected software versions for CVE-2022-22951 are 8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4, and 8.8.x prior to 8.8.2.
What is the description of CVE-2022-22951?
CVE-2022-22951 is an OS command injection vulnerability in VMware Carbon Black App Control.
How can I fix CVE-2022-22951?
To fix CVE-2022-22951, update VMware Carbon Black App Control to version 8.5.14, 8.6.6, 8.7.4, or 8.8.2.