CVE-2022-31704 is a critical broken access control vulnerability affecting VMware vRealize Log Insight. An unauthenticated attacker can remotely inject code into sensitive files, leading to remote code execution. With a CVSS score of 9.8 (Critical), this flaw is easily exploitable over the network with low attack complexity, allowing for complete compromise of confidentiality, integrity, and availability. Public exploit modules are available, including a Metasploit module and Nuclei templates, and it has garnered significant community discussion and media coverage, indicating high awareness and potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 4.8CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.10.2CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.