CVE-2022-31703
published 2022-12-14CVE-2022-31703: The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.79%
75.8th percentile
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | vrealize_log_insight | <= 8.10.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v2g5-92j4-qq7q: vRealize Network Insight (vRNI) directory traversal vulnerability in vRNI REST API
ghsa_unreviewed·2022-12-14
CVE-2022-31703 [HIGH] CWE-22 GHSA-v2g5-92j4-qq7q: vRealize Network Insight (vRNI) directory traversal vulnerability in vRNI REST API
vRealize Network Insight (vRNI) directory traversal vulnerability in vRNI REST API. A malicious actor with network access to the vRNI REST API can read arbitrary files from the server.
VMware
VMware vRealize Network Insight (vRNI) updates address command injection and directory traversal security vulnerabilities (CVE-2022-31702, CVE-2022-31703)
vendor_vmware·2022-12-13·CVSS 9.8
CVE-2022-31702 [CRITICAL] VMware vRealize Network Insight (vRNI) updates address command injection and directory traversal security vulnerabilities (CVE-2022-31702, CVE-2022-31703)
VMSA-2022-0031: VMware vRealize Network Insight (vRNI) updates address command injection and directory traversal security vulnerabilities (CVE-2022-31702, CVE-2022-31703)
vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. VMware has evaluated the severity of this issue to be in the critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2022-31702, CVE-2022-31703
Affected products: VMware vRealize
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-14
Published