CVE-2022-31698
published 2022-12-13CVE-2022-31698: The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter…
PriorityP344medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
47.80%
98.7th percentile
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
| vmware | cloud_foundation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)
vendor_vmware·2022-12-08·CVSS 8.8
CVE-2022-31696 [HIGH] VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)
VMSA-2022-0030: VMware ESXi and vCenter Server updates address multiple security vulnerabilities (CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699)
VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.5.
CVEs: CVE-2022-31696, CVE-2022-31697, CVE-2022-31698, CVE-2022-31699
Affected products: VMware Cloud Foundation, VMware ESXi, VMware vCenter Server, VMware vSphere
GHSA
GHSA-9qpg-6x42-3rc4: The vCenter Server contains a denial-of-service vulnerability in the content library service
ghsa_unreviewed·2022-12-13
CVE-2022-31698 [MEDIUM] CWE-400 GHSA-9qpg-6x42-3rc4: The vCenter Server contains a denial-of-service vulnerability in the content library service
The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Denial-of-service vulnerability discovered in VMWare vCenter
blogs_talos·2022-12-13·CVSS 5.3
CVE-2022-31698 [MEDIUM] Vulnerability Spotlight: Denial-of-service vulnerability discovered in VMWare vCenter
Cisco Talos recently discovered a denial-of-service vulnerability in VMWare vCenter Server.
VMware vCenter Server is a platform that enables centralized control and monitoring over all virtual machines and EXSi hypervisors included in vSphere.
TALOS-2022-1588 (CVE-2022-31698) concerns a pre-authentication denial-of-service vulnerability in a handler of the content library. A specially crafted HTTP header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
Cisco Talos worked with VMWare to ensure that this issue is resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy.
Users are encouraged to update the affected product as soon as possible: VMware vCenter Server 6.5 Update 3t
Talos
Vulnerability Spotlight: Denial-of-service vulnerability discovered in VMWare vCenter
blogs_talos·2022-12-13·CVSS 5.3
CVE-2022-31698 [MEDIUM] Vulnerability Spotlight: Denial-of-service vulnerability discovered in VMWare vCenter
## Vulnerability Spotlight: Denial-of-service vulnerability discovered in VMWare vCenter
Cisco Talos recently discovered a denial-of-service vulnerability in VMWare vCenter Server.
VMware vCenter Server is a platform that enables centralized control and monitoring over all virtual machines and EXSi hypervisors included in vSphere.
TALOS-2022-1588 (CVE-2022-31698) concerns a pre-authentication denial-of-service vulnerability in a handler of the content library. A specially crafted HTTP header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
Cisco Talos worked with VMWare to ensure that this issue is resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosure policy .
Users are encoura
2022-12-13
Published