PatchSiren

PatchSiren cyber security CVE debrief

CVE-2022-22948 VMware CVE debrief

CVE-2022-22948 is described as an incorrect default file permissions issue in VMware vCenter Server. CISA includes it in the Known Exploited Vulnerabilities catalog, so defenders should treat it as a priority remediation item and follow VMware's guidance without delay.

Vendor
VMware
Product
vCenter Server
CVSS
Unknown
CISA KEV
Listed
Original CVE published
2024-07-17
Original CVE updated
2024-07-17
Advisory published
2024-07-17
Advisory updated
2024-07-17

Who should care

Teams that administer VMware vCenter Server, especially those responsible for virtualization management, system hardening, and privileged access controls. Incident response and vulnerability management teams should also track it because CISA has placed it in KEV.

Technical summary

The vulnerability is characterized in the supplied sources as incorrect default file permissions in VMware vCenter Server. That class of issue can weaken access control expectations around server-side files, so the defensive focus is on vendor guidance, mitigations, and verification of least-privilege file access after remediation.

Defensive priority

High. CISA's Known Exploited Vulnerabilities listing and due date indicate this should be handled urgently for any exposed or in-scope vCenter Server deployment.

Recommended defensive actions

  • Confirm whether VMware vCenter Server is deployed anywhere in the environment, including management networks and lab systems.
  • Review VMware advisory VMSA-2022-0009 and apply the vendor-recommended mitigations or updates.
  • Use the CISA KEV dateAdded of 2024-07-17 and dueDate of 2024-08-07 to drive remediation tracking and exception handling.
  • If mitigations are unavailable, follow CISA guidance to discontinue use of the product.
  • After remediation, verify file permissions and access controls remain aligned with least-privilege expectations.

Evidence notes

The supplied source corpus identifies VMware vCenter Server as the affected product and records the vulnerability in CISA's KEV feed with dateAdded 2024-07-17 and dueDate 2024-08-07. The KEV metadata also points to VMware advisory VMSA-2022-0009 and the NVD entry for CVE-2022-22948.

Sources and references

Verified primary and authoritative sources

  • CVE-2022-22948 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2022-22948

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2022-22948 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2022-22948

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.