CVE-2022-31697
Severity
5.5MEDIUM
EPSS
0.1%
top 79.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 13
Description
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-j724-gwg9-qjvw: The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext↗2022-12-13
CVEList▶
CVE-2022-31697: The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext↗2022-12-13
📋Vendor Advisories
1VMware▶
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)↗2022-12-08