CVE-2022-31680
Last modified
CVE-2022-31680 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.. EPSS estimates a 33.06% chance of exploitation in the next 30 days.
Description
The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Vcenter Server | < 6.5 |
| Vmware | Vcenter Server | 6.5 |
References
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1587Exploit, Third Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1587Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31680?
How severe is CVE-2022-31680?
How do I fix CVE-2022-31680?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31675VMware vRealize Operations contains an authentication bypass…7.5
- CVE-2022-31676VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local pr…7.8
- CVE-2022-31677An Insufficient Session Expiration issue was discovered in t…5.4
- CVE-2022-31678VMware Cloud Foundation (NSX-V) contains an XML External Ent…9.1
- CVE-2022-31679Applications that allow HTTP PATCH access to resources expos…3.7
- CVE-2022-3168Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-31681VMware ESXi contains a null-pointer deference vulnerability.…6.5
- CVE-2022-31682VMware Aria Operations contains an arbitrary file read vulne…4.9
- CVE-2022-31683Concourse (7.x.y prior to 7.8.3 and 6.x.y prior to 6.7.9) co…5.4
- CVE-2022-31684Reactor Netty HTTP Server, in versions 1.0.11 - 1.0.23, may …4.3
- CVE-2022-31685VMware Workspace ONE Assist prior to 22.10 contains an Authe…9.8
- CVE-2022-31686VMware Workspace ONE Assist prior to 22.10 contains a Broken…9.8
Are you affected by CVE-2022-31680?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
