Cyber Resilience

CVE-2022-22972

Vmware Cloud Foundation 3.0 … 4.3.1

High EPSS
Published
20 May 2022
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 9.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.56 99th percentile
Risk Priority 97 floored blend · peak EPSS

Summary

CVE-2022-22972 is a critical-severity an unspecified weakness vulnerability in Vmware Cloud Foundation. Its CVSS base score is 9.8 (Critical).

Operationally, ranked in the top 1% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-3 (Access Enforcement) and IA-2 (Identification and Authentication (Organizational Users)) — see the control section below for these in your framework.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

VMware Workspace ONE Access, Identity Manager, and vRealize Automation contain an authentication bypass vulnerability that affects local domain users. The flaw permits an unauthenticated attacker to reach the product UI over the network and obtain administrative privileges, corresponding to a CVSS 3.1 base score of 9.8.

An attacker with network access to the affected user-interface endpoints can exploit the weakness without supplying credentials, resulting in full administrative control over the compromised instance. The attack requires no user interaction and no prior privileges.

VMware published advisory VMSA-2022-0014 to address the issue. The EPSS score for this CVE has remained consistently high, with a current value of 0.9368 and a recorded peak of 0.9376.

EU & UK References

Vulnerability Data

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.

CWE(s)

Related Threats

Likely ATT&CK TechniquesAI

Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.

T1190 Exploit Public-Facing Application Initial Accessconfidence: HIGH
The vulnerability is an authentication bypass in a public-facing UI, directly enabling remote exploitation of the application without credentials.
T1078 Valid Accounts Stealthconfidence: HIGH
Successful exploitation grants full administrative privileges, allowing the attacker to operate with valid high-privileged accounts on the system.
inferred from description · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2022-22960Same product: Linux Linux Kernel
CVE-2022-22954Same product: Linux Linux Kernel
CVE-2022-22956Same product: Linux Linux Kernel
CVE-2023-20884Same product: Linux Linux Kernel
CVE-2020-4006Same product: Linux Linux Kernel
CVE-2023-1582Same product: Linux Linux Kernel
CVE-2023-52792Same product: Linux Linux Kernel
CVE-2024-35859Same product: Linux Linux Kernel
CVE-2023-52825Same product: Linux Linux Kernel
CVE-2024-56554Same product: Linux Linux Kernel

Affected Assets

vmware
identity manager
3.3.3, 3.3.4, 3.3.5, 3.3.6
vmware
vrealize automation
7.6
vmware
workspace one access
20.10.0.0, 20.10.0.1, 21.08.0.0, 21.08.0.1
vmware
cloud foundation
3.0, 3.0.1, 3.0.1.1, 3.10, 3.10.1
vmware
vrealize suite lifecycle manager
8.0, 8.0.1, 8.1, 8.2, 8.3

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • AC-3 Access Enforcement
  • IA-2 Identification and Authentication (Organizational Users)
  • SC-7 Boundary Protection
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Directly enforces authentication requirements on UI endpoints so the bypass cannot grant admin access without credentials.

prevent

Mandates identification and authentication of organizational users before any access to the Workspace ONE / Identity Manager UI is allowed.

prevent

Restricts network reachability of the management UI to only authorized sources, reducing the attack surface for unauthenticated exploitation.

References