CVE-2022-31697
MEDIUM
5,5
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
Description
AI Translation Available
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0005
Percentile
0,2th
Updated
EPSS Score Trend (Last 90 Days)
312
Cleartext Storage of Sensitive Information
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies:
Cloud Computing, ICS/OT, Mobile
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update1b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3h:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3m:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3n:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update2a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3f:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update1c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3q:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update2c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update2b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Cloud Foundation by Vmware
Version Range Affected
From
3.0
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3p:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update1e:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3s:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3k:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update2a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3f:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update2c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update1b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3r:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3g:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3r:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3l:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3p:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update1:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update2d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update1a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update2b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3g:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3e:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update1g:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3f:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update3d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3q:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update2d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3t:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update2c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:a:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3j:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update3n:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update2g:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:c:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.7:update3o:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:update2:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:6.5:update1d:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Vcenter Server by Vmware
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:vcenter_server:7.0:b:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.vmware.com/security/advisories/VMSA-2022-0030.html
https://www.vmware.com/security/advisories/VMSA-2022-0030.html