← Vulnerability feed

Vulnerability record · CVE-2022-22948 · published 29 March 2022

CVE-2022-22948: VMware vCenter Server information disclosure via incorrect file permissions

Vmware · Cloud Foundation

vCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because the data exposed can include credentials or configuration secrets, the flaw matters beyond a simple read: it can feed follow-on access to the management plane. The record does not specify which files or what exact data is exposed.

6.5 CVSS 3.1 Medium CISA KEV since 17 Jul 2024 EPSS 13% · top 3.7% CWE-276 · Incorrect default permissions
6.5CVSS 3.1 base score, v2 4.0
13%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityIt is listed in CISA KEV with confirmed in-the-wild exploitation and a high EPSS percentile, though the CVSS base score is only 6.5 and impact is limited to confidentiality.

What it is

vCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because the data exposed can include credentials or configuration secrets, the flaw matters beyond a simple read: it can feed follow-on access to the management plane. The record does not specify which files or what exact data is exposed.

Impact

An attacker with a low-privileged account gains access to sensitive information on the vCenter Server, with high confidentiality impact and no integrity or availability effect. That information can enable further compromise of the virtualized environment.

Attack surface

Reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). Any authenticated non-administrative vCenter user is the likely entry point; the record does not state whether unauthenticated access is possible.

Exploitation

CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-17 with a remediation due date of 2024-08-07, indicating exploitation in the wild. EPSS is 0.13282 (96th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the vendor patch per VMware advisory VMSA-2022-0009, or discontinue use of the product if mitigations are unavailable, as directed by CISA.
  • Audit and correct file and directory permissions on vCenter Server hosts to remove world- or group-readable sensitive files.
  • Restrict and review non-administrative vCenter accounts, removing unnecessary accounts and tightening role assignments.
  • Rotate credentials and secrets that may have been exposed through readable files.
  • Monitor for and investigate any signs of lateral movement from vCenter into ESXi or other management components.

Detection

  • Review vCenter file and directory permissions for unexpected world- or group-readable sensitive files.
  • Audit authentication and access logs for non-administrative accounts reading unusual files or paths.
  • Hunt for post-exploitation activity from vCenter hosts, such as new administrative sessions or credential use from unexpected sources.
  • Track patch status of vCenter Server and Cloud Foundation against VMSA-2022-0009.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-22948 to the Known Exploited Vulnerabilities catalog on 17 July 2024 as "VMware vCenter Server Incorrect Default File Permissions Vulnerability ". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 August 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-22948 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed9.8CVE-2024-38813VMware vCenter Server privilege escalation to root via crafted packetvCenter Server contains a privilege escalation flaw where a malicious actor with network access can send a specially crafted network packet to escala…KEVEPSS 17%analysed9.8CVE-2024-38812VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-based buffer overflow (CWE-122/CWE-787) in its DCERPC protocol implementation. A remote, unauthenticated attacker can …KEVEPSS 55%analysed9.8CVE-2024-37079VMware vCenter Server DCERPC heap overflow allows remote code executionvCenter Server contains a heap-overflow (out-of-bounds write) in its DCERPC protocol implementation. A remote, unauthenticated attacker can send a cr…KEVEPSS 22%analysed9.8CVE-2023-34048VMware vCenter Server DCERPC out-of-bounds writevCenter Server contains an out-of-bounds write in its DCERPC protocol implementation. A remote, unauthenticated attacker with network access can trig…KEVEPSS 99%analysed9.8CVE-2022-22954VMware Workspace ONE Access and Identity Manager server-side template injection RCEVMware Workspace ONE Access and Identity Manager are affected by a server-side template injection flaw that allows remote code execution. A network-r…KEVEPSS 100%analysed9.8CVE-2021-22005VMware vCenter Server Analytics arbitrary file upload to RCEThe Analytics service in VMware vCenter Server accepts a specially crafted file upload, which the product mishandles as a path traversal issue (CWE-2…KEVEPSS 100%analysed9.8CVE-2021-21985VMware vCenter Server Virtual SAN Health Check plug-in RCEThe vSphere Client (HTML5) in vCenter Server fails to validate input in the Virtual SAN Health Check plug-in, which is enabled by default. This allow…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2022-22948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.