Vulnerability record · CVE-2022-22948 · published 29 March 2022
CVE-2022-22948: VMware vCenter Server information disclosure via incorrect file permissions
Vmware · Cloud Foundation
vCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because the data exposed can include credentials or configuration secrets, the flaw matters beyond a simple read: it can feed follow-on access to the management plane. The record does not specify which files or what exact data is exposed.
Description
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityIt is listed in CISA KEV with confirmed in-the-wild exploitation and a high EPSS percentile, though the CVSS base score is only 6.5 and impact is limited to confidentiality.
What it is
vCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because the data exposed can include credentials or configuration secrets, the flaw matters beyond a simple read: it can feed follow-on access to the management plane. The record does not specify which files or what exact data is exposed.
Impact
An attacker with a low-privileged account gains access to sensitive information on the vCenter Server, with high confidentiality impact and no integrity or availability effect. That information can enable further compromise of the virtualized environment.
Attack surface
Reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). Any authenticated non-administrative vCenter user is the likely entry point; the record does not state whether unauthenticated access is possible.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17 with a remediation due date of 2024-08-07, indicating exploitation in the wild. EPSS is 0.13282 (96th percentile), and no ransomware campaign use is documented.
What to do
- Apply the vendor patch per VMware advisory VMSA-2022-0009, or discontinue use of the product if mitigations are unavailable, as directed by CISA.
- Audit and correct file and directory permissions on vCenter Server hosts to remove world- or group-readable sensitive files.
- Restrict and review non-administrative vCenter accounts, removing unnecessary accounts and tightening role assignments.
- Rotate credentials and secrets that may have been exposed through readable files.
- Monitor for and investigate any signs of lateral movement from vCenter into ESXi or other management components.
Detection
- Review vCenter file and directory permissions for unexpected world- or group-readable sensitive files.
- Audit authentication and access logs for non-administrative accounts reading unusual files or paths.
- Hunt for post-exploitation activity from vCenter hosts, such as new administrative sessions or credential use from unexpected sources.
- Track patch status of vCenter Server and Cloud Foundation against VMSA-2022-0009.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-22948 to the Known Exploited Vulnerabilities catalog on 17 July 2024 as "VMware vCenter Server Incorrect Default File Permissions Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 August 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.vmware.com/security/advisories/VMSA-2022-0009.html | PatchVendor Advisory |
| https://www.vmware.com/security/advisories/VMSA-2022-0009.html | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22948 | US Government Resource |
Track CVE-2022-22948 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-22948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.