CVE-2022-22972
Vmware Cloud Foundation 3.0 … 4.3.1
Raw vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2022-22972 is a critical-severity an unspecified weakness vulnerability in Vmware Cloud Foundation. Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and IA-2 (Identification and Authentication (Organizational Users)) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain an authentication bypass vulnerability that affects local domain users. The flaw permits an unauthenticated attacker to reach the product UI over the network and obtain administrative privileges, corresponding to a CVSS 3.1 base score of 9.8.
An attacker with network access to the affected user-interface endpoints can exploit the weakness without supplying credentials, resulting in full administrative control over the compromised instance. The attack requires no user interaction and no prior privileges.
VMware published advisory VMSA-2022-0014 to address the issue. The EPSS score for this CVE has remained consistently high, with a current value of 0.9368 and a recorded peak of 0.9376.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-28088
Vulnerability Data
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
- CWE(s)
Related Threats
Likely ATT&CK TechniquesAI
Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly enforces authentication requirements on UI endpoints so the bypass cannot grant admin access without credentials.
Mandates identification and authentication of organizational users before any access to the Workspace ONE / Identity Manager UI is allowed.
Restricts network reachability of the management UI to only authorized sources, reducing the attack surface for unauthenticated exploitation.