CVE-2022-22945
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
16/02/2022
Last modified:
24/02/2022
Description
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | 3.0 (including) | 3.11 (including) |
| cpe:2.3:a:vmware:nsx_data_center:*:*:*:*:*:vsphere:*:* | 6.4.13 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



