CVE-2022-22951

Severity
9.1CRITICAL
EPSS
3.0%
top 13.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMar 24

Description

VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App Control administration interface may be able to execute commands on the server due to improper input validation leading to remote code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 2.3 | Impact: 6.0

Affected Packages2 packages

NVDvmware/carbon_black_app_control8.58.5.14+3
CVEListV5vmware_carbon_black_app_control_(appc)VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hgxf-8v8v-6qg4: VMware Carbon Black App Control (82022-03-24
CVEList
CVE-2022-22951: VMware Carbon Black App Control (82022-03-23

📋Vendor Advisories

1
VMware
VMware Carbon Black App Control update addresses multiple vulnerabilities (CVE-2022-22951, CVE-2022-22952)2022-03-23