9.1
CVE-2022-22952
- EPSS 0.62%
- Published 23.03.2022 20:15:10
- Last modified 21.11.2024 06:47:40
- Source security@vmware.com
- Teams watchlist Login
- Open Login
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface may be able to execute code on the Windows instance where AppC Server is installed by uploading a specially crafted file.
Data is provided by the National Vulnerability Database (NVD)
VMware ≫ Carbon Black App Control Version >= 8.5 < 8.5.14
VMware ≫ Carbon Black App Control Version >= 8.6 < 8.6.6
VMware ≫ Carbon Black App Control Version >= 8.7.0 < 8.7.4
VMware ≫ Carbon Black App Control Version >= 8.8.0 < 8.8.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.62% | 0.69 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.