CVE-2022-22954
CRITICAL KEV RANSOMWARE NUCLEIVMware Workspace ONE Access CVE-2022-22954
Title source: metasploitDescription
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
Exploits (28)
nomisec
WORKING POC
282 stars
by sherlocksecurity · remote
https://github.com/sherlocksecurity/VMware-CVE-2022-22954
nomisec
WRITEUP
11 stars
by Vulnmachines · poc
https://github.com/Vulnmachines/VMWare_CVE-2022-22954
nomisec
WORKING POC
10 stars
by DrorDvash · remote
https://github.com/DrorDvash/CVE-2022-22954_VMware_PoC
nomisec
WORKING POC
8 stars
by orwagodfather · remote
https://github.com/orwagodfather/CVE-2022-22954
nomisec
WORKING POC
1 stars
by emilyastranova · poc
https://github.com/emilyastranova/VMware-CVE-2022-22954-Command-Injector
metasploit
WORKING POC
EXCELLENT
by mr_me, Udhaya Prakash, wvu · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_workspace_one_access_cve_2022_22954.rb
Nuclei Templates (1)
VMware Workspace ONE Access - Server-Side Template Injection
CRITICALby sherlocksecurity
Shodan:
http.favicon.hash:-1250474341
FOFA:
icon_hash=-1250474341 || app="vmware-workspace-one-access" || app="vmware-identity-manager" || app="vmware-vrealize"
References (3)
Scores
CVSS v3
9.8
EPSS
0.9444
EPSS Percentile
100.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2022-04-14
VulnCheck KEV
2022-04-06
InTheWild.io
2022-04-13
ENISA EUVD
EUVD-2022-28077
Ransomware Use
Confirmed
CWE
CWE-94
Status
published
Products (11)
vmware/cloud_foundation
4.0 - 4.3.1
vmware/identity_manager
3.3.3
vmware/identity_manager
3.3.4
vmware/identity_manager
3.3.5
vmware/identity_manager
3.3.6
vmware/vrealize_automation
7.6
vmware/vrealize_suite_lifecycle_manager
8.0 - 8.2
vmware/workspace_one_access
20.10.0.0
vmware/workspace_one_access
20.10.0.1
vmware/workspace_one_access
21.08.0.0
... and 1 more
Published
Apr 11, 2022
KEV Added
Apr 14, 2022
Tracked Since
Feb 18, 2026