CVE-2022-22956 is a critical authentication bypass vulnerability affecting VMware Workspace ONE Access and other related VMware products, allowing an unauthenticated attacker to bypass the authentication mechanism and execute arbitrary operations. With a CVSS score of 9.8 (CRITICAL), this vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While not currently on CISA's KEV catalog, exploit modules are publicly available in Metasploit and Nuclei, and it has garnered significant community discussion and media attention, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.3CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.3:*:*:*:*:*:*:* | ||
3.3.4CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.4:*:*:*:*:*:*:* | ||
3.3.5CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.5:*:*:*:*:*:*:* | ||
3.3.6CPE matchmatch criteria | cpe:2.3:a:vmware:identity_manager:3.3.6:*:*:*:*:*:*:* | ||
>= 8.0, < 9.0CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_automation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.