CVE-2022-31706 is a critical Directory Traversal Vulnerability affecting VMware vRealize Log Insight. An unauthenticated attacker can inject files into the operating system, leading to remote code execution. This vulnerability has a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, exploit modules for Metasploit and Nuclei templates are publicly available, and it has garnered significant community discussion and media coverage, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 4.8CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.10.2CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.