VMware vCenter Server Incorrect Default File Permissions Vulnerability

北京赛克艾威科技有限公司 2024-07-17


  • 漏洞编号:CVE-2022-22948
  • 漏洞等级:严重
  • 漏洞标签:VMware、vCenter Server、在野利用
  • 发布时间:2024-07-17

漏洞描述

VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.

修复建议

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

参考链接

https://www.vmware.com/security/advisories/VMSA-2022-0009.html

https://www.cisa.gov/known-exploited-vulnerabilities-catalog