« Volver al listado

CVE-2022-22966

Estado: ModificadaAlta (7.2)—

An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability to gain access to the server.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-22966",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "VMware Cloud Director",
          "versions": [
            {
              "status": "affected",
              "version": "VMware Cloud Director versions prior to 10.3.3, 10.2.2.3, 10.1.4.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-04-14T21:15:08.600",
  "references": [
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2022-0013.html",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2022-0013.html",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability to gain access to the server."
    },
    {
      "lang": "es",
      "value": "Un actor malicioso autenticado muy privilegiado con acceso a la red del inquilino o proveedor de VMware Cloud Director puede ser capaz de explotar una vulnerabilidad de ejecución de código remota para obtener acceso al servidor"
    }
  ],
  "lastModified": "2026-06-17T04:29:15.817",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:vcloud_director:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92DF630B-0F1A-4364-B8E7-CEF34135E297",
              "versionEndExcluding": "10.1.4.1",
              "versionStartIncluding": "10.1.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcloud_director:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2125091-2392-4A73-8D86-CBD6A2A212CA",
              "versionEndExcluding": "10.2.2.3",
              "versionStartIncluding": "10.2.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vcloud_director:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "91A567BC-6739-475C-A58E-C045C19757D8",
              "versionEndExcluding": "10.3.3",
              "versionStartIncluding": "10.3.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}