Vulnerability record · CVE-2022-31706 · published 26 January 2023
CVE-2022-31706: VMware vRealize Log Insight directory traversal leading to RCE
Vmware · Vrealize Log Insight
vRealize Log Insight contains a directory traversal flaw (CWE-22) that lets an unauthenticated attacker write files into the appliance's operating system. Because the injected files can be executed, the flaw escalates from path traversal to remote code execution. It matters because the affected appliance is network-facing and the attack requires no credentials or user interaction.
Description
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable path traversal that yields remote code execution, with a 9.8 CVSS score and very high EPSS probability.
What it is
vRealize Log Insight contains a directory traversal flaw (CWE-22) that lets an unauthenticated attacker write files into the appliance's operating system. Because the injected files can be executed, the flaw escalates from path traversal to remote code execution. It matters because the affected appliance is network-facing and the attack requires no credentials or user interaction.
Impact
An unauthenticated attacker can write arbitrary files to the underlying OS and achieve remote code execution, gaining full control of the appliance with high confidentiality, integrity and availability impact.
Attack surface
Reachable over the network via the appliance's HTTP interface (CVSS vector AV:N/AC:L/PR:N/UI:N), requiring no authentication and no user interaction.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.87, 99.7th percentile) and public exploit write-ups exist on Packet Storm, indicating active interest.
What to do
- Apply the vendor patch per VMware advisory VMSA-2023-0001 as the first action.
- If immediate patching is not possible, restrict network access to the Log Insight interface to trusted management networks only.
- Monitor the appliance filesystem for unexpected or newly written files and review for signs of injected content.
- Rebuild or reimage any appliance suspected of compromise, since file injection can persist.
- Track vendor advisory updates for any revised fixed versions or workarounds.
Detection
- Alert on anomalous file creation or modification in appliance OS paths outside normal log storage.
- Monitor HTTP requests to the Log Insight web interface for traversal sequences such as ../ in URLs or parameters.
- Watch for unexpected outbound connections or new processes spawned by the Log Insight service.
- Correlate unauthenticated requests to the appliance with subsequent file writes or process execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-31706 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-31706), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.