SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-31700

VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability.

HIGH 7.2EPSS 1.08%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
1.08% probability · 63th percentile
CISA KEV
Not listed
Affected
vmware/access · vmware/cloud foundation · vmware/identity manager
Source
security@vmware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.