Vulnerability Description
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Vrealize Log Insight | >= 3.0, <= 4.8 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/174606/VMware-vRealize-Log-Insight-Unauthen
- https://www.vmware.com/security/advisories/VMSA-2023-0001.htmlPatchVendor Advisory
- http://packetstormsecurity.com/files/174606/VMware-vRealize-Log-Insight-Unauthen
- https://www.vmware.com/security/advisories/VMSA-2023-0001.htmlPatchVendor Advisory
- https://packetstorm.news/files/id/174606
FAQ
What is CVE-2022-31704?
CVE-2022-31704 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in r...
How severe is CVE-2022-31704?
CVE-2022-31704 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-31704?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Vrealize Log Insight.