CVE-2022-22954

CRITICAL KEV RANSOMWARE NUCLEI

VMware Workspace ONE Access CVE-2022-22954

Title source: metasploit

Description

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

Exploits (28)

nomisec WORKING POC 1,464 stars
by Schira4396 · remote
https://github.com/Schira4396/VcenterKiller
nomisec WORKING POC 282 stars
by sherlocksecurity · remote
https://github.com/sherlocksecurity/VMware-CVE-2022-22954
nomisec WORKING POC 70 stars
by bewhale · poc
https://github.com/bewhale/CVE-2022-22954
nomisec WORKING POC 16 stars
by tunelko · remote
https://github.com/tunelko/CVE-2022-22954-PoC
nomisec WORKING POC 12 stars
by jax7sec · remote
https://github.com/jax7sec/CVE-2022-22954
nomisec WRITEUP 11 stars
by Vulnmachines · poc
https://github.com/Vulnmachines/VMWare_CVE-2022-22954
nomisec WORKING POC 10 stars
by DrorDvash · remote
https://github.com/DrorDvash/CVE-2022-22954_VMware_PoC
nomisec WORKING POC 8 stars
by orwagodfather · remote
https://github.com/orwagodfather/CVE-2022-22954
nomisec WORKING POC 4 stars
by b4dboy17 · poc
https://github.com/b4dboy17/CVE-2022-22954
nomisec WORKING POC 4 stars
by aniqfakhrul · poc
https://github.com/aniqfakhrul/CVE-2022-22954
nomisec WORKING POC 4 stars
by MLX15 · poc
https://github.com/MLX15/CVE-2022-22954
nomisec WORKING POC 3 stars
by Chocapikk · poc
https://github.com/Chocapikk/CVE-2022-22954
nomisec WORKING POC 2 stars
by axingde · poc
https://github.com/axingde/CVE-2022-22954-POC
nomisec SCANNER 2 stars
by bb33bb · poc
https://github.com/bb33bb/CVE-2022-22954-VMware-RCE
nomisec WRITEUP 1 stars
by corelight · poc
https://github.com/corelight/cve-2022-22954
nomisec WORKING POC 1 stars
by emilyastranova · poc
https://github.com/emilyastranova/VMware-CVE-2022-22954-Command-Injector
nomisec SCANNER 1 stars
by mumu2020629 · poc
https://github.com/mumu2020629/-CVE-2022-22954-scanner
nomisec SCANNER 1 stars
by MSeymenD · poc
https://github.com/MSeymenD/CVE-2022-22954-Testi
nomisec WRITEUP
by arzuozkan · poc
https://github.com/arzuozkan/CVE-2022-22954
nomisec WORKING POC
by amit-pathak009 · poc
https://github.com/amit-pathak009/CVE-2022-22954
nomisec WORKING POC
by secfb · poc
https://github.com/secfb/CVE-2022-22954
nomisec WORKING POC
by amit-pathak009 · poc
https://github.com/amit-pathak009/CVE-2022-22954-PoC
nomisec WRITEUP
by nguyenv1nK · poc
https://github.com/nguyenv1nK/CVE-2022-22954
nomisec WORKING POC
by Jun-5heng · remote
https://github.com/Jun-5heng/CVE-2022-22954
nomisec WORKING POC
by mhurts · poc
https://github.com/mhurts/CVE-2022-22954-POC
nomisec WORKING POC
by lucksec · poc
https://github.com/lucksec/VMware-CVE-2022-22954
vulncheck_xdb WRITEUP
remote
https://github.com/pedrib/PoC
metasploit WORKING POC EXCELLENT
by mr_me, Udhaya Prakash, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb

Nuclei Templates (1)

VMware Workspace ONE Access - Server-Side Template Injection
CRITICALby sherlocksecurity
Shodan: http.favicon.hash:-1250474341
FOFA: icon_hash=-1250474341 || app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize"

Scores

CVSS v3 9.8
EPSS 0.9444
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-04-14
VulnCheck KEV 2022-04-06
InTheWild.io 2022-04-13
ENISA EUVD EUVD-2022-28077
Ransomware Use Confirmed
CWE
CWE-94
Status published
Products (11)
vmware/cloud_foundation 4.0 - 4.3.1
vmware/identity_manager 3.3.3
vmware/identity_manager 3.3.4
vmware/identity_manager 3.3.5
vmware/identity_manager 3.3.6
vmware/vrealize_automation 7.6
vmware/vrealize_suite_lifecycle_manager 8.0 - 8.2
vmware/workspace_one_access 20.10.0.0
vmware/workspace_one_access 20.10.0.1
vmware/workspace_one_access 21.08.0.0
... and 1 more
Published Apr 11, 2022
KEV Added Apr 14, 2022
Tracked Since Feb 18, 2026