cbcvebase.
CVE-2022-22948
published 2022-03-29

CVE-2022-22948: The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to…

PriorityP277medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2024-08-07
Exploited in the wild
EPSS
13.94%
96.1th percentile
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

Affected

5 ranges
VendorProductVersion rangeFixed in
vmwarecloud_foundation>= 3.0 < 3.113.11
vmwarecloud_foundation>= 4.0 < 4.4.14.4.1
vmwarevcenter_server
vmwarevcenter_server
vmwarevcenter_server

Detection & IOCsextracted from sources · hover to see the quote

  • UNC3886 exploited CVE-2022-22948 to extract encrypted credentials from the vCenter PostgreSQL database (postgresDB); monitor for unauthorized read access to vCenter credential/config files with improper permissions
  • Post-exploitation tool 'vcenter_secrets_dump' (Metasploit module post/linux/gather/vcenter_secrets_dump.rb) targets vCenter appliance root shells to harvest dcAccountDN, dcAccountPassword, MACHINE_SSL, VMCA_ROOT, and SSO IdP certificates with private keys — monitor for execution of this module or equivalent file access patterns on vCenter appliances
  • Monitor for harvesting and reuse of vCenter Server service accounts following exploitation of CVE-2022-22948, as UNC3886 leveraged these for lateral movement
  • CVE-2022-22948 is actively exploited in the wild (CISA KEV); prioritize detection of non-administrative access to sensitive vCenter files with incorrect default permissions
  • ·The Metasploit post-exploitation module only works against the vCenter Linux appliance, not Windows vCenter instances
  • ·CVE-2022-22948 requires non-administrative (but authenticated) access to vCenter Server to exploit; it is not an unauthenticated remote code execution vulnerability
  • ·UNC3886 has demonstrated the capability to replace indicators mentioned in open-source threat intelligence within under a week of publication, reducing the longevity of any specific IOCs associated with this CVE

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.