CVE-2022-31711

MEDIUM EXPLOITED NUCLEI

VMware vRealize Log Insight 3.0-4.8 - Unauthenticated Exposure of Sensitive Session Information

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-31711 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Horizon3.ai Attack Team, including a Metasploit module exploits/linux/http/vmware_vrli_rce. A Nuclei detection template is also available.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2022-31711, which leverages multiple vulnerabilities in VMware vRealize Log Insight to achieve arbitrary file write and remote code execution. The exploit chains CVE-2022-31711 (info leak), CVE-2022-31704 (broken access control), and CVE-2022-31706 (directory traversal) to write a malicious cron job for a reverse shell.

Description

VMware vRealize Log Insight contains an Information Disclosure Vulnerability. A malicious actor can remotely collect sensitive session and application information without authentication.

Exploits (2)

vulncheck_xdb WORKING POC
infoleak
https://github.com/horizon3ai/vRealizeLogInsightRCE

This repository contains a functional exploit for CVE-2022-31711, which leverages multiple vulnerabilities in VMware vRealize Log Insight to achieve arbitrary file write and remote code execution. The exploit chains CVE-2022-31711 (info leak), CVE-2022-31704 (broken access control), and CVE-2022-31706 (directory traversal) to write a malicious cron job for a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware vRealize Log Insight (versions affected by VMSA-2023-0001)
No auth needed
Prerequisites: Network access to the target's Thrift RPC endpoint (default port 16520) · Ability to host an HTTP server for payload delivery
devstral-2 · analyzed Feb 25, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Horizon3.ai Attack Team · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/vmware_vrli_rce.rb

This Metasploit module exploits a chain of vulnerabilities in VMware vRealize Log Insight (CVE-2022-31706, CVE-2022-31704, CVE-2022-31711) to achieve unauthenticated remote code execution as root. It leverages Thrift service commands to download and process a malicious PAK archive, placing a JSP payload for execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: VMware vRealize Log Insight < 8.10.2
No auth needed
Prerequisites: Network access to Thrift service (port 16520) and web service (port 443) · Target running vulnerable VMware vRealize Log Insight version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

VMware vRealize Log Insight < v8.10.2 - Information Disclosure
MEDIUMby DhiyaneshDK
Shodan: http.title:"vrealize log insight"
FOFA: title="vrealize log insight"

Scores

CVSS v3 5.3
EPSS 0.8241
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2023-12-20
CWE
CWE-200
Status published
Products (1)
vmware/vrealize_log_insight 3.0 - 4.8
Published Jan 26, 2023
Tracked Since Feb 18, 2026