9.1
CVE-2022-31680
- EPSS 0.86%
- Published 07.10.2022 21:15:11
- Last modified 21.11.2024 07:05:06
- Source security@vmware.com
- Teams watchlist Login
- Open Login
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
Data is provided by the National Vulnerability Database (NVD)
VMware ≫ Vcenter Server Version < 6.5
VMware ≫ Vcenter Server Version6.5 Update-
VMware ≫ Vcenter Server Version6.5 Updatea
VMware ≫ Vcenter Server Version6.5 Updateb
VMware ≫ Vcenter Server Version6.5 Updatec
VMware ≫ Vcenter Server Version6.5 Updated
VMware ≫ Vcenter Server Version6.5 Updateupdate1
VMware ≫ Vcenter Server Version6.5 Updateupdate1b
VMware ≫ Vcenter Server Version6.5 Updateupdate1c
VMware ≫ Vcenter Server Version6.5 Updateupdate1d
VMware ≫ Vcenter Server Version6.5 Updateupdate1e
VMware ≫ Vcenter Server Version6.5 Updateupdate1g
VMware ≫ Vcenter Server Version6.5 Updateupdate2
VMware ≫ Vcenter Server Version6.5 Updateupdate2b
VMware ≫ Vcenter Server Version6.5 Updateupdate2c
VMware ≫ Vcenter Server Version6.5 Updateupdate2d
VMware ≫ Vcenter Server Version6.5 Updateupdate2g
VMware ≫ Vcenter Server Version6.5 Updateupdate3
VMware ≫ Vcenter Server Version6.5 Updateupdate3d
VMware ≫ Vcenter Server Version6.5 Updateupdate3f
VMware ≫ Vcenter Server Version6.5 Updateupdate3k
VMware ≫ Vcenter Server Version6.5 Updateupdate3n
VMware ≫ Vcenter Server Version6.5 Updateupdate3p
VMware ≫ Vcenter Server Version6.5 Updateupdate3q
VMware ≫ Vcenter Server Version6.5 Updateupdate3r
VMware ≫ Vcenter Server Version6.5 Updateupdate3s
VMware ≫ Vcenter Server Version6.5 Updateupdate3t
VMware ≫ Vcenter Server Version6.5 Updateupdate3u
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.86% | 0.741 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.1 | 2.3 | 6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.