{"id":"CVE-2022-22948","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-22948","summary":"The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit…","details":"The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.","published":"2022-03-29T17:24:33.000Z","modified":"2025-10-21T23:15:43.268Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.13282,"percentile":0.96097,"asOf":"2026-08-26"},"cisaKev":{"dateAdded":"2024-07-17","dueDate":"2024-08-07","knownRansomwareCampaignUse":false},"exploitsKnown":6,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.vmware.com/security/advisories/VMSA-2022-0009.html"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22948"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T23:15:43.268Z"}}