CVE-2022-31702: Command Injection
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31702?
CVE-2022-31702 is a command injection vulnerability in vRealize Network Insight (vRNI) REST API.
What is the severity of CVE-2022-31702?
CVE-2022-31702 has a severity rating of 9.8, which is considered critical.
How does CVE-2022-31702 impact vRealize Network Insight (vRNI)?
CVE-2022-31702 allows malicious actors with network access to the vRNI REST API to execute commands without authentication.
Which versions of vRealize Network Insight (vRNI) are affected by CVE-2022-31702?
vRealize Network Insight versions 6.2.0, 6.3.0, 6.4.0, 6.5.1, 6.6.0, and 6.7.0 are affected by CVE-2022-31702.
How can I fix CVE-2022-31702?
To fix CVE-2022-31702, it is recommended to apply the necessary security patches provided by VMware. Refer to the VMware security advisory for more details.