CVE-2022-22954 is a critical remote code execution vulnerability affecting VMware Workspace ONE Access and Identity Manager, stemming from a server-side template injection flaw. With a CVSS score of 9.8, it allows unauthenticated attackers with network access to execute arbitrary code, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited, including in ransomware campaigns, with public exploit modules available in Metasploit and Nuclei. The high EPSS score, FAUCET Risk Score, extensive media coverage, and community discussion underscore its severe and immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.3CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:* | ||
3.3.4CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:* | ||
3.3.5CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:* | ||
3.3.6CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:* | ||
7.6CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_automation:7.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.