CVE-2022-31697: Medium severity vmware vcenter vulnerability
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31697?
CVE-2022-31697 has a medium severity rating due to its potential for information disclosure.
How do I fix CVE-2022-31697?
To fix CVE-2022-31697, users should upgrade to a patched version of VMware vCenter Server as recommended by VMware.
What versions of VMware vCenter are affected by CVE-2022-31697?
CVE-2022-31697 affects VMware vCenter Server versions 6.5 and 6.7 as well as 7.0.
What kind of vulnerability is CVE-2022-31697?
CVE-2022-31697 is an information disclosure vulnerability that allows logging of credentials in plaintext.
Who can exploit CVE-2022-31697?
A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation can exploit CVE-2022-31697.