CVE-2022-31697 (GCVE-0-2022-31697)
Vulnerability from cvelistv5
Published
2022-12-13 00:00
Modified
2025-04-22 15:50
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- Information disclosure vulnerability
Summary
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
References
► | URL | Tags | |
---|---|---|---|
Impacted products
Vendor | Product | Version | ||
---|---|---|---|---|
n/a | VMware vCenter Server, VMware Cloud Foundation |
Version: VMware (7.0 prior to 7.0 U3i, 6.7 prior to 6.7.0 U3s, 6.5 prior to 6.5 U3u), VMware Cloud Foundation (4.x, 3.x) |
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-03T07:26:00.990Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_transferred" ], "url": "https://www.vmware.com/security/advisories/VMSA-2022-0030.html" } ], "title": "CVE Program Container" }, { "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "LOCAL", "availabilityImpact": "NONE", "baseScore": 5.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" } }, { "other": { "content": { "id": "CVE-2022-31697", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "timestamp": "2025-04-22T15:49:52.808479Z", "version": "2.0.3" }, "type": "ssvc" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-312", "description": "CWE-312 Cleartext Storage of Sensitive Information", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-04-22T15:50:24.431Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "product": "VMware vCenter Server, VMware Cloud Foundation", "vendor": "n/a", "versions": [ { "status": "affected", "version": "VMware (7.0 prior to 7.0 U3i, 6.7 prior to 6.7.0 U3s, 6.5 prior to 6.5 U3u), VMware Cloud Foundation (4.x, 3.x)" } ] } ], "descriptions": [ { "lang": "en", "value": "The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation." } ], "problemTypes": [ { "descriptions": [ { "description": "Information disclosure vulnerability", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2022-12-13T00:00:00.000Z", "orgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d", "shortName": "vmware" }, "references": [ { "url": "https://www.vmware.com/security/advisories/VMSA-2022-0030.html" } ] } }, "cveMetadata": { "assignerOrgId": "dcf2e128-44bd-42ed-91e8-88f912c1401d", "assignerShortName": "vmware", "cveId": "CVE-2022-31697", "datePublished": "2022-12-13T00:00:00.000Z", "dateReserved": "2022-05-25T00:00:00.000Z", "dateUpdated": "2025-04-22T15:50:24.431Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2022-31697\",\"sourceIdentifier\":\"security@vmware.com\",\"published\":\"2022-12-13T16:15:19.790\",\"lastModified\":\"2025-04-22T16:15:29.520\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.\"},{\"lang\":\"es\",\"value\":\"vCenter Server contiene una vulnerabilidad de divulgaci\u00f3n de informaci\u00f3n debido al registro de credenciales en texto plano. Un actor malintencionado con acceso a una estaci\u00f3n de trabajo que invoc\u00f3 una operaci\u00f3n ISO de vCenter Server Appliance (instalar/actualizar/migrar/restaurar) puede acceder a las contrase\u00f1as de texto plano utilizadas durante esa operaci\u00f3n.\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\",\"baseScore\":5.5,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"LOCAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"LOW\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":1.8,\"impactScore\":3.6},{\"source\":\"134c704f-9b21-4f2e-91b3-4a467353bcc0\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\",\"baseScore\":5.5,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"LOCAL\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"LOW\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":1.8,\"impactScore\":3.6}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-312\"}]},{\"source\":\"134c704f-9b21-4f2e-91b3-4a467353bcc0\",\"type\":\"Secondary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-312\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"23CFE5A5-A166-4FD5-BE97-5F16DAB1EAE0\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*\",\"matchCriteriaId\":\"CF7DDB0C-3C07-4B5E-8B8A-0542FEE72877\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*\",\"matchCriteriaId\":\"1DD16169-A7DF-4604-888C-156A60018E32\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*\",\"matchCriteriaId\":\"46FC9F34-C8FA-4AFE-9F4A-7CF9516BD4D9\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*\",\"matchCriteriaId\":\"D26534EB-327B-4ED6-A3E1-005552CB1F9D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update1:*:*:*:*:*:*\",\"matchCriteriaId\":\"7E51F433-1152-4E94-AF77-970230B1A574\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update1b:*:*:*:*:*:*\",\"matchCriteriaId\":\"0064D104-E0D8-481A-9029-D3726A1A9CF4\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*\",\"matchCriteriaId\":\"F72A1E9C-F960-4E8C-A46C-B38209E6349E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*\",\"matchCriteriaId\":\"2C33CE46-F529-4EA9-9344-6ED3BFA7019D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*\",\"matchCriteriaId\":\"9F1D8161-0E02-45C9-BF61-14799AB65E03\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*\",\"matchCriteriaId\":\"1F2CB1FF-6118-4875-945D-07BAA3A21FFA\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*\",\"matchCriteriaId\":\"1AEDA28A-5C8E-4E95-A377-3BE530DBEAB5\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*\",\"matchCriteriaId\":\"BDDC6510-3116-4578-80C8-8EF044A8370A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*\",\"matchCriteriaId\":\"8678DB48-CB98-4E4C-ADE6-CABA73265FEC\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*\",\"matchCriteriaId\":\"DBD9A341-1FBF-4E04-848B-550DEB27261A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*\",\"matchCriteriaId\":\"4955663C-1BB6-4F3E-9D4B-362DF144B7F1\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*\",\"matchCriteriaId\":\"CE0F8453-3D6C-4F1C-9167-3F02E3D905DC\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*\",\"matchCriteriaId\":\"0EAD4045-A7F9-464F-ABB9-3782941162CC\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3k:*:*:*:*:*:*\",\"matchCriteriaId\":\"2F0A79C2-33AE-40C5-A853-770A4C691F29\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3n:*:*:*:*:*:*\",\"matchCriteriaId\":\"D8BB6CBC-11D6-40A4-ABAF-53AB9BED5A73\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3p:*:*:*:*:*:*\",\"matchCriteriaId\":\"26A3EC15-8C04-49AD-9045-4D9FADBD50CD\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3q:*:*:*:*:*:*\",\"matchCriteriaId\":\"AF7E87BB-1B5B-4F13-A70C-B3C6716E7919\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3r:*:*:*:*:*:*\",\"matchCriteriaId\":\"70A9244F-2C9C-4D7D-B384-08DDF95770DA\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3s:*:*:*:*:*:*\",\"matchCriteriaId\":\"2CBEA4F8-CBA3-4C71-96B3-47489F0D299C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.5:update3t:*:*:*:*:*:*\",\"matchCriteriaId\":\"B40B0E23-410D-403D-811B-486EBF406E6D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"E456F84C-A86E-4EA9-9A3E-BEEA662136E6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*\",\"matchCriteriaId\":\"5241C282-A02B-44B2-B6CA-BA3A99F9737C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*\",\"matchCriteriaId\":\"04A60AC7-C2EA-4DBF-9743-54D708584AFA\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:c:*:*:*:*:*:*\",\"matchCriteriaId\":\"445FA649-B7F4-4AE2-A487-57357AC95241\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*\",\"matchCriteriaId\":\"8A91B0C4-F184-459E-AFD3-DE0E351CC964\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*\",\"matchCriteriaId\":\"23253631-2655-48A8-9B00-CB984232329C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*\",\"matchCriteriaId\":\"50C2A9A8-0E66-4702-BCD4-74622108E7A6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*\",\"matchCriteriaId\":\"EE4D3E2A-C32D-408F-B811-EF8BC86F0D34\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*\",\"matchCriteriaId\":\"31CA7802-D78D-4BAD-A45A-68B601C010C6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*\",\"matchCriteriaId\":\"3B98981B-4721-4752-BAB4-361DB5AEB86F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3:*:*:*:*:*:*\",\"matchCriteriaId\":\"04487105-980A-4943-9360-4442BF0411E6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3a:*:*:*:*:*:*\",\"matchCriteriaId\":\"24D24E06-EB3F-4F11-849B-E66757B01466\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3b:*:*:*:*:*:*\",\"matchCriteriaId\":\"8AF12716-88E2-44B5-ACD7-BCBECA130FB8\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3f:*:*:*:*:*:*\",\"matchCriteriaId\":\"3352212C-E820-47B3-BDF5-57018F5B9E81\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3g:*:*:*:*:*:*\",\"matchCriteriaId\":\"6436ADFD-6B94-4D2A-B09B-CED4EC6CA276\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3j:*:*:*:*:*:*\",\"matchCriteriaId\":\"D06832CE-F946-469D-B495-6735F18D02A0\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3l:*:*:*:*:*:*\",\"matchCriteriaId\":\"726AC46D-9EA8-4FE8-94B8-0562935458F2\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3m:*:*:*:*:*:*\",\"matchCriteriaId\":\"0243D22F-1591-4A95-A7FE-2658CEE0C08F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3n:*:*:*:*:*:*\",\"matchCriteriaId\":\"02AE5983-CD14-4EAF-9F5C-1281E3DE7F46\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3o:*:*:*:*:*:*\",\"matchCriteriaId\":\"EFDDF4CA-1C20-430E-A17C-CC2998F8BDDF\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3p:*:*:*:*:*:*\",\"matchCriteriaId\":\"7D2B0FBA-8E4A-491E-8E22-AAD7DBB5FF5A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3q:*:*:*:*:*:*\",\"matchCriteriaId\":\"126B4E78-DCE3-4375-80C9-3679F9BF107C\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:6.7:update3r:*:*:*:*:*:*\",\"matchCriteriaId\":\"5D7808C1-9548-4BAE-8EC5-6C406185757F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"5FA81CCD-A05E-498C-820E-21980E92132F\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*\",\"matchCriteriaId\":\"0EE83406-A3D9-4F75-A1A6-63831CEBEEC1\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*\",\"matchCriteriaId\":\"FB563627-C9CF-4D8A-B882-9AB65EAE9E15\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*\",\"matchCriteriaId\":\"DCA03B2A-48B2-48AD-B8EB-9D7BB2016819\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*\",\"matchCriteriaId\":\"A2392D0F-D7A2-4E01-9212-1BA6C895AEBF\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*\",\"matchCriteriaId\":\"6D731C1A-9FE5-461C-97E2-6F45E4CBABE1\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*\",\"matchCriteriaId\":\"8725E544-2A94-4829-A683-1ECCE57A74A6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:*\",\"matchCriteriaId\":\"0FC6765A-6584-45A8-9B21-4951D2EA8939\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:*\",\"matchCriteriaId\":\"F4CA36C1-732E-41AE-B847-F7411B753F3D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:*\",\"matchCriteriaId\":\"0DA882B6-D811-4E4B-B614-2D48F0B9036E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:*\",\"matchCriteriaId\":\"8D30A78E-16D0-4A2E-A2F8-F6073698243E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:*\",\"matchCriteriaId\":\"188E103E-9568-4CE0-A984-141B2A9E82D2\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:*\",\"matchCriteriaId\":\"B266439F-E911-4C95-9D27-88DF96DDCCD5\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:*\",\"matchCriteriaId\":\"6508A908-EF14-4A72-AC75-5DA6F8B98A0E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:*\",\"matchCriteriaId\":\"3BAD2012-5C82-4EA9-A780-9BF1DA5A18AB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:*\",\"matchCriteriaId\":\"58597F18-0B23-4D21-9ABA-D9773958F10E\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:*\",\"matchCriteriaId\":\"ADF46C54-313B-4742-A074-EEA0A6554680\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:*\",\"matchCriteriaId\":\"9587F800-57BC-44B6-870E-95691684FC46\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3f:*:*:*:*:*:*\",\"matchCriteriaId\":\"AD148A75-5076-416D-AFD6-0F281DA0A82B\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3g:*:*:*:*:*:*\",\"matchCriteriaId\":\"956CEA8C-F8C4-41BD-85B4-44FE3A772E50\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:vcenter_server:7.0:update3h:*:*:*:*:*:*\",\"matchCriteriaId\":\"008AEA0F-116B-4AF8-B3A7-3041CCE25235\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"3.0\",\"matchCriteriaId\":\"22B1BC2E-BF28-4256-AA6C-468023C859EC\"}]}]}],\"references\":[{\"url\":\"https://www.vmware.com/security/advisories/VMSA-2022-0030.html\",\"source\":\"security@vmware.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://www.vmware.com/security/advisories/VMSA-2022-0030.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]}]}}", "vulnrichment": { "containers": "{\"adp\": [{\"title\": \"CVE Program Container\", \"references\": [{\"url\": \"https://www.vmware.com/security/advisories/VMSA-2022-0030.html\", \"tags\": [\"x_transferred\"]}], \"providerMetadata\": {\"orgId\": \"af854a3a-2127-422b-91ae-364da2661108\", \"shortName\": \"CVE\", \"dateUpdated\": \"2024-08-03T07:26:00.990Z\"}}, {\"title\": \"CISA ADP Vulnrichment\", \"metrics\": [{\"cvssV3_1\": {\"scope\": \"UNCHANGED\", \"version\": \"3.1\", \"baseScore\": 5.5, \"attackVector\": \"LOCAL\", \"baseSeverity\": \"MEDIUM\", \"vectorString\": \"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N\", \"integrityImpact\": \"NONE\", \"userInteraction\": \"NONE\", \"attackComplexity\": \"LOW\", \"availabilityImpact\": \"NONE\", \"privilegesRequired\": \"LOW\", \"confidentialityImpact\": \"HIGH\"}}, {\"other\": {\"type\": \"ssvc\", \"content\": {\"id\": \"CVE-2022-31697\", \"role\": \"CISA Coordinator\", \"options\": [{\"Exploitation\": \"none\"}, {\"Automatable\": \"no\"}, {\"Technical Impact\": \"partial\"}], \"version\": \"2.0.3\", \"timestamp\": \"2025-04-22T15:49:52.808479Z\"}}}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"CWE\", \"cweId\": \"CWE-312\", \"description\": \"CWE-312 Cleartext Storage of Sensitive Information\"}]}], \"providerMetadata\": {\"orgId\": \"134c704f-9b21-4f2e-91b3-4a467353bcc0\", \"shortName\": \"CISA-ADP\", \"dateUpdated\": \"2025-04-22T15:50:18.096Z\"}}], \"cna\": {\"affected\": [{\"vendor\": \"n/a\", \"product\": \"VMware vCenter Server, VMware Cloud Foundation\", \"versions\": [{\"status\": \"affected\", \"version\": \"VMware (7.0 prior to 7.0 U3i, 6.7 prior to 6.7.0 U3s, 6.5 prior to 6.5 U3u), VMware Cloud Foundation (4.x, 3.x)\"}]}], \"references\": [{\"url\": \"https://www.vmware.com/security/advisories/VMSA-2022-0030.html\"}], \"descriptions\": [{\"lang\": \"en\", \"value\": \"The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.\"}], \"problemTypes\": [{\"descriptions\": [{\"lang\": \"en\", \"type\": \"text\", \"description\": \"Information disclosure vulnerability\"}]}], \"providerMetadata\": {\"orgId\": \"dcf2e128-44bd-42ed-91e8-88f912c1401d\", \"shortName\": \"vmware\", \"dateUpdated\": \"2022-12-13T00:00:00.000Z\"}}}", "cveMetadata": "{\"cveId\": \"CVE-2022-31697\", \"state\": \"PUBLISHED\", \"dateUpdated\": \"2025-04-22T15:50:24.431Z\", \"dateReserved\": \"2022-05-25T00:00:00.000Z\", \"assignerOrgId\": \"dcf2e128-44bd-42ed-91e8-88f912c1401d\", \"datePublished\": \"2022-12-13T00:00:00.000Z\", \"assignerShortName\": \"vmware\"}", "dataType": "CVE_RECORD", "dataVersion": "5.1" } } }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…