« Volver al listado

CVE-2022-31702

Estado: ModificadaCrítica (9.8)—

vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-31702",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2022-31702",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-22T16:03:18.690780Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "VMware vRealize Network Insight (vRNI)",
          "versions": [
            {
              "status": "affected",
              "version": "6.x"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-12-14T19:15:13.047",
  "references": [
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2022-0031.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2022-0031.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-77"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication."
    },
    {
      "lang": "es",
      "value": "vRealize Network Insight (vRNI) contiene una vulnerabilidad de inyección de comandos presente en la API REST de vRNI. Un actor malintencionado con acceso a la red de la API REST de vRNI puede ejecutar comandos sin autenticación."
    }
  ],
  "lastModified": "2026-06-17T04:46:07.793",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:vrealize_network_insight:6.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BC96796-6141-4DC2-8278-1DE9BD0882C2"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vrealize_network_insight:6.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "962DF5E6-4CDF-460C-A78D-68466ECFB93F"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vrealize_network_insight:6.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37CB4762-F4FE-4AB0-8466-0E8169220687"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vrealize_network_insight:6.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37C4DB4F-24F6-408A-B560-409B1489BDAB"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vrealize_network_insight:6.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B5EA4ED-3343-451F-82C2-CBB3B3E8210C"
            },
            {
              "criteria": "cpe:2.3:a:vmware:vrealize_network_insight:6.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE6C4EE3-C7F2-4137-9F73-C6BF57E70FEA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}