cbcvebase.
CVE-2022-31680
published 2022-10-07

CVE-2022-31680: The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter…

PriorityP266critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
33.06%
98.2th percentile
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.

Affected

2 ranges
VendorProductVersion rangeFixed in
vmwarevcenter_server< 6.56.5
vmwarevcenter_server

Detection & IOCsextracted from sources · hover to see the quote

snort
60433
  • Trigger condition: a specially crafted HTTP request sent to the targeted vCenter machine by an authenticated attacker exploiting Java deserialization in the PSC component.
  • ·Exploitation requires prior authentication (admin-level credentials) to vCenter Server; this is a post-authentication vulnerability, not unauthenticated RCE.
  • ·Snort rule 60433 may be updated as additional vulnerability information becomes available; always pull the latest rule from Firepower Management Center or Snort.org.
  • ·Confirmed vulnerable version is VMware vCenter Server 6.5 update 3t; testing was performed against this specific version.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.