peter bassill · operator
$ cve CVE-2022-31680 JSON

CVE-2022-31680

9.1
CRITICAL · CVSS 3.1 · EPSS 33.1% (pctl 98)

Patch early

EPSS 33.1% — above the 10% action threshold.

Description

The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts the vCenter Server.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS33.06% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2022-10-07
Last modified2026-06-17

Affected (1)

VendorProduct
vmwarevcenter server

References

→ the Explorer  ·  watch your stack  ·  NVD