VMSA-2022-0005

vmware logo header

Important


VMSA-2022-0005.1

8.8

2022-02-15

2022-03-14

CVE-2022-22945

VMware NSX Data Center for vSphere update addresses CLI shell injection vulnerability (CVE-2022-22945)

1. Impacted Products

  • VMware NSX Data Center for vSphere (NSX-V)
  • VMware Cloud Foundation (Cloud Foundation)

2. Introduction

A CLI shell injection vulnerability affecting VMware NSX Data Center for vSphere was privately reported to VMware. Updates are available to address this vulnerability in affected VMware products.

3. VMware NSX Data Center for vSphere update addresses CLI shell injection vulnerability (CVE-2022-22945)

Description

VMware NSX Data Center for vSphere contains a CLI shell injection vulnerability in the NSX Edge appliance component. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.8.

Known Attack Vectors

A malicious actor with SSH access to an NSX-Edge appliance (NSX-V) can execute arbitrary commands on the operating system as root.

Resolution

To remediate CVE-2022-22945 apply the patches listed in the ‘Fixed Version’ column of the ‘Response Matrix’ below.

Workarounds

Workarounds for CVE-2022-22945 have been listed in the ‘Workarounds’ column of the ‘Response Matrix’ below.

Additional Documentation

Additional documentation for CVE-2022-22945 have been listed in the ‘Additional Documentation’ column of the ‘Response Matrix’ for Cloud Foundation (NSX-V) below.

Notes

None

Acknowledgements

VMware would like to thank Dimitri Di Cristofaro (@d_glenx) and Przemek Reszke (@kolokokop) from SECFORCE LTD for reporting this issue to us.

Response Matrix

ProductVersionRunning OnCVE IdentifierCVSSv3SeverityFixed VersionWorkaroundsAdditional Documentation
NSX Data Center for vSphere
Any
Any
CVE-2022-22945
important

None

Impacted Product Suites that Deploy Response Matrix Components:

ProductVersionRunning OnCVE IdentifierCVSSv3SeverityFixed VersionWorkaroundsAdditional Documentation
Cloud Foundation (NSX-V)
3.x
Any
CVE-2022-22945
important

Patch Pending

4. References

5. Change Log

2022-02-15: VMSA-2022-0005
Initial security advisory.

 

2022-03-14: VMSA-2022-0005.1
Updated security advisory Response Matrix to include workarounds and additional documentation.

6. Contact

E-mail list for product security notifications and announcements:

https://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce

 

This Security Advisory is posted to the following lists:  

security-announce@lists.vmware.com  

 

E-mail: security@vmware.com

PGP key at:

https://kb.vmware.com/kb/1055 

 

VMware Security Advisories

https://www.vmware.com/security/advisories 

 

VMware Security Response Policy

https://www.vmware.com/support/policies/security_response.html 

 

VMware Lifecycle Support Phases

https://www.vmware.com/support/policies/lifecycle.html 

 

VMware Security & Compliance Blog  

https://blogs.vmware.com/security 

 

Twitter

https://twitter.com/VMwareSRC

 

Copyright 2022 VMware Inc. All rights reserved.
 

Read full article (vmware.com)

All content and images belong to their respected owners, this article is for informational purposes only.

Total
0
Shares
Leave a Reply
Previous Post
vmware logo header

VMSA-2022-0004

Next Post
vmware logo header

VMSA-2022-0007

Related Posts