CVE-2022-31680
published 2022-10-07CVE-2022-31680: The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter…
PriorityP266critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
33.06%
98.2th percentile
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vcenter_server | < 6.5 | 6.5 |
| vmware | vcenter_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
60433
- →Trigger condition: a specially crafted HTTP request sent to the targeted vCenter machine by an authenticated attacker exploiting Java deserialization in the PSC component. ↗
- ·Exploitation requires prior authentication (admin-level credentials) to vCenter Server; this is a post-authentication vulnerability, not unauthenticated RCE. ↗
- ·Snort rule 60433 may be updated as additional vulnerability information becomes available; always pull the latest rule from Firepower Management Center or Snort.org. ↗
- ·Confirmed vulnerable version is VMware vCenter Server 6.5 update 3t; testing was performed against this specific version. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31680, CVE-2022-31681)
vendor_vmware·2022-10-06·CVSS 9.1
CVE-2022-31680 [CRITICAL] VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31680, CVE-2022-31681)
VMSA-2022-0025: VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31680, CVE-2022-31681)
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.
CVEs: CVE-2022-31680, CVE-2022-31681
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vCenter Server, VMware vSphere
GHSA
GHSA-5g3f-j849-rm6p: The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller)
ghsa_unreviewed·2022-10-08
CVE-2022-31680 [CRITICAL] CWE-502 GHSA-5g3f-j849-rm6p: The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller)
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
blogs_talos·2022-10-11·CVSS 9.1
[CRITICAL] Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
## Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable data deserialization vulnerability in the VMware vCenter server platform.
VMware is one of the most popular virtual machine solutions currently available, and its vCenter software allows users to manage an entire environment of VMs. The vulnerability Talos discovered is a post-authentication Java deserialization issue that could corrupt the software in a way that could allow an attacker to exploit arbitrary code on the target machine.
TALOS-2022-1587 (CVE-2022-31680) is triggered if an adversary sends a specially crafted HTTP request to a targeted machine. The attacker wo
Talos
Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
blogs_talos·2022-10-11·CVSS 9.1
[CRITICAL] Vulnerability Spotlight: Data deserialization in VMware vCenter could lead to remote code execution
Marcin “Icewall” Noga of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered an exploitable data deserialization vulnerability in the VMware vCenter server platform.
VMware is one of the most popular virtual machine solutions currently available, and its vCenter software allows users to manage an entire environment of VMs. The vulnerability Talos discovered is a post-authentication Java deserialization issue that could corrupt the software in a way that could allow an attacker to exploit arbitrary code on the target machine.
TALOS-2022-1587 (CVE-2022-31680) is triggered if an adversary sends a specially crafted HTTP request to a targeted machine. The attacker would first have to log in with legitimate credentials to vCenter to be successful.
Cisco Talos worked wi
2022-10-07
Published