CVE-2022-35776
published 2022-08-09CVE-2022-35776: Azure Site Recovery Denial of Service Vulnerability
PriorityP416medium6.2CVSS 3.1
AVAACLPRHUINSCCNINAH
EPSS
0.79%
51.8th percentile
Azure Site Recovery Denial of Service Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_site_recovery_vmware_to_azure | < 9.50.6419.1 | 9.50.6419.1 |
| microsoft | azure_site_recovery_vmware_to_azure | >= 9.0 < 9.50 | 9.50 |
| msrc | azure_site_recovery_vmware_to_azure | — | — |
CVSS provenance
nvdv3.16.2MEDIUMCVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
vendor_msrc6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-grc6-9mfg-jh27: Azure Site Recovery Denial of Service Vulnerability
ghsa_unreviewed·2022-08-10
CVE-2022-35776 [MEDIUM] CWE-400 GHSA-grc6-9mfg-jh27: Azure Site Recovery Denial of Service Vulnerability
Azure Site Recovery Denial of Service Vulnerability.
Microsoft
Azure Site Recovery Denial of Service Vulnerability
vendor_msrc·2022-08-09·CVSS 6.2
CVE-2022-35776 [MEDIUM] Azure Site Recovery Denial of Service Vulnerability
Azure Site Recovery Denial of Service Vulnerability
FAQ: According to the CVSS score, the attack vector is adjacent (AV:A). What does this mean for this vulnerability?
Exploiting this vulnerability requires an attacker to be within the VNET associated with the vulnerable configuration server.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
The vulnerability is in the configuration server but also impacts the process server.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What privileges does an attacker require to exploit this vulnerability?
Successful exploitation of this vulnerability requires an attacker to compromise admin credentials to one of the VMs associated with
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-09
Published