CVE-2022-46996

CRITICAL

vSphere_selfuse < commit - RCE

Title source: llm
STIX 2.1

Description

vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.

Scores

CVSS v3 9.8
EPSS 0.0071
EPSS Percentile 72.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-912
Status published
Products (1)
vsphere_selfuse_project/vsphere_selfuse 2019-07-22
Published Dec 14, 2022
Tracked Since Feb 18, 2026