CVE-2022-22951 is an OS command injection vulnerability affecting VMware Carbon Black App Control versions 8.5.x, 8.6.x, 8.7.x, and 8.8.x. An authenticated, high-privileged attacker with network access to the administration interface can execute arbitrary commands on the server due to improper input validation, leading to remote code execution. This vulnerability is rated as Critical (CVSS 9.1) due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) are currently available and it is not listed in CISA's KEV catalog, there has been limited community discussion and media coverage, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.5, < 8.5.14CPE matchmatch criteria | cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:* | ||
>= 8.6, < 8.6.6CPE matchmatch criteria | cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:* | ||
>= 8.7.0, < 8.7.4CPE matchmatch criteria | cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:* | ||
>= 8.8.0, < 8.8.2CPE matchmatch criteria | cpe:2.3:a:vmware:carbon_black_app_control:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.