CVE-2022-31711
MEDIUM EXPLOITED NUCLEIVMware vRealize Log Insight 3.0-4.8 - Unauthenticated Exposure of Sensitive Session Information
Title source: llmExploitation Summary
CVE-2022-31711 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including Horizon3.ai Attack Team, including a Metasploit module exploits/linux/http/vmware_vrli_rce.
A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-31711, which leverages multiple vulnerabilities in VMware vRealize Log Insight to achieve arbitrary file write and remote code execution. The exploit chains CVE-2022-31711 (info leak), CVE-2022-31704 (broken access control), and CVE-2022-31706 (directory traversal) to write a malicious cron job for a reverse shell.
Description
VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.
Exploits (2)
This repository contains a functional exploit for CVE-2022-31711, which leverages multiple vulnerabilities in VMware vRealize Log Insight to achieve arbitrary file write and remote code execution. The exploit chains CVE-2022-31711 (info leak), CVE-2022-31704 (broken access control), and CVE-2022-31706 (directory traversal) to write a malicious cron job for a reverse shell.
This Metasploit module exploits a chain of vulnerabilities in VMware vRealize Log Insight (CVE-2022-31706, CVE-2022-31704, CVE-2022-31711) to achieve unauthenticated remote code execution as root. It leverages Thrift service commands to download and process a malicious PAK archive, placing a JSP payload for execution.
Nuclei Templates (1)
http.title:"vrealize log insight"
title="vrealize log insight"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N