🔙 목록으로 돌아가기

CVE-2022-31704: VMware vRealize Log Insight - Improper Access Control to RCE

TitleVMware vRealize Log Insight - Improper Access Control to RCE
Authorritikchaddha
SeverityCritical
ImpactSuccessful exploitation allows a remote, unauthenticated attacker to inject and execute malicious code on the target appliance, potentially resulting in complete compromise of the affected system.
RemediationUpdate VMware vRealize Log Insight to version 8.10.2 or later, as detailed in the official vendor advisory.
CVSS Score9.8
EPSS Score0.90011
CVE IDCVE-2022-31704
CWE IDCWE-22
Shodan Queryhttp.title:"vrealize log insight"
Fofa Querytitle="vrealize log insight"
Tags cve cve2022 vmware vrealize rce lfi passive vkev vuln

🔍 Vulnerability Description

The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.

🌐 HTTP Request

GET /i18n/component/JS?locale=en-US HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:69.0) Gecko/20100101 Firefox/69.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
GET /api/v1/version HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36 Edge/15.15063
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-31704.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-31704.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A