CVE-2022-31710 is a deserialization vulnerability in VMware vRealize Log Insight that allows an unauthenticated attacker to remotely trigger a denial of service. This high-severity vulnerability (CVSS 7.5) requires no user interaction and has low attack complexity, making it easily exploitable. While not currently listed in CISA's KEV catalog, there is significant community discussion and media coverage, including reports of exploit code availability and active exploitation. Organizations using vRealize Log Insight should prioritize patching to mitigate the risk of service disruption.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, <= 4.8CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* | ||
>= 8.0.0, < 8.10.2CPE matchmatch criteria | cpe:2.3:a:vmware:vrealize_log_insight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.