CVE-2022-31697

Severity
5.5MEDIUM
EPSS
0.1%
top 79.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13

Description

The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-j724-gwg9-qjvw: The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext2022-12-13
CVEList
CVE-2022-31697: The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext2022-12-13

📋Vendor Advisories

1
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)2022-12-08
CVE-2022-31697 (MEDIUM CVSS 5.5) | The vCenter Server contains an info | cvebase.io