EXPOSURES › CVE-2022-22948
CVE-2022-22948
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware vCenter Server shipped with incorrect default file permissions enabling remote privileged attackers to access sensitive data.
This vulnerability allows remote attackers with elevated privileges to access sensitive information due to misconfigured default file permissions in vCenter Server. DIB organizations must ensure vCenter instances are hardened immediately to prevent unauthorized data exposure and potential compliance violations under NIST 800-171.
Shame score — The vulnerability stems from incorrect default configurations rather than a deliberate security flaw, though it represents a missed opportunity to ship hardened defaults.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |