PT-2022-5903 · Vmware · Vrealize Network Insight+1

Published

2022-12-13

·

Updated

2023-03-01

·

CVE-2022-31703

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions vRealize Log Insight (affected versions not specified) vRealize Network Insight (affected versions not specified)
Description The issue concerns a Directory Traversal Vulnerability in the vRealize Log Insight and vRealize Network Insight. This vulnerability allows an unauthenticated, malicious actor to inject files into the operating system of an impacted appliance, potentially resulting in remote code execution. It also enables a malicious actor with network access to the vRNI REST API to read arbitrary files from the server.
Recommendations For vRealize Log Insight, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For vRealize Network Insight, consider restricting access to the vRNI REST API to minimize the risk of exploitation. As a temporary workaround, avoid using the downloadFile functionality until a patch is available.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2022-07319
CVE-2022-31703
ZDI-23-056

Affected Products

Vrealize Log Insight
Vrealize Network Insight