CVE detail
CVE-2022-31706
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 19.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
- 6th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 6th February, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHE Check Point Research has flagged the Dingo crypto Token, with a market cap of $10,941,525 as a scam. The threat actors behind the token added a backdoor function in its smart contract, to […]
vendorresearch.checkpoint.comFeb 6, 2023, 4:07 PM - Security Affairs newsletter Round 405 by Pierluigi PaganiniSecurity Affairs
A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. CISA adds Oracle, SugarCRM bugs to its Known Exploited Vulnerabilities Catalog GoAnywhere MFT zero-day flaw actively […]
newssecurityaffairs.comFeb 5, 2023, 9:50 AM - VMware Workstation update fixes an arbitrary file deletion bugSecurity Affairs
VMware addressed a high-severity privilege escalation vulnerability, tracked as CVE-2023-20854, in VMware Workstation. VMware fixed a high-severity privilege escalation flaw, tracked as CVE-2023-20854, that impacts Workstation. An attacker can exploit the vulnerability to delete arbitrary files on Workstation version 17.x for Windows OS. “An arbitrary file deletion vulnerability in VMware Workstation was privately reported to VMware. Updates are […]
newssecurityaffairs.comFeb 3, 2023, 2:06 PM VMware published patches last week for four vulnerabilities in its vRealize Log Insight product that, if combined, could allow attackers to take over the log collection and analytics platform. This week, a proof-of-concept exploit chain has been released by security researchers, along with detailed explanations for each vulnerability, meaning in-the-wild attacks could soon follow. “Gaining […]
newswww.csoonline.comFeb 2, 2023, 9:21 PMVMware confirms the publication of exploit code and urged VMware vRealize Log Insight users to implement mitigations immediately.
newswww.securityweek.comFeb 1, 2023, 4:34 PMHorizon3 security researchers released proof-of-concept (PoC) code for VMware vRealize Log Insight RCE vulnerability CVE-2022-31706. Last week, researchers from Horizon3’s Attack Team announced the release of PoC exploit code for remote code execution in VMware vRealize Log tracked as CVE-2022-31706 (CVSS base 9.8/10). The PoC exploit code will trigger a series of flaws in VMware […]
newssecurityaffairs.comJan 31, 2023, 6:44 PMIntroduction The recent VMware VMSA describes four new CVEs affecting VMware vRealize Log Insight, reported by ZDI. Three of these CVEs can be combined to give an attacker remote code execution as root. This vulnerability is exploitable in the default configuration for VMware vRealize Log Insight. We have successfully reproduced this exploit and would like […]
exploithorizon3.aiJan 31, 2023, 11:53 AMHorizon3’s Attack Team made the headlines again announcing the release of a PoC exploit code for remote code execution in VMware vRealize Log. Researchers from the Horizon3’s Attack Team announced the release of PoC exploit code for remote code execution in VMware vRealize Log. The PoC exploit code will trigger a series of flaws in […]
newssecurityaffairs.comJan 29, 2023, 2:37 PM- Week in review: ChatGPT cybersecurity, critical RCE vulnerabilities found in git, Riot Games breachedHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: BSidesZG 2023: Strengthening the infosec community in Croatia’s capital In March 2023, Zagreb will be added to the (already long) list of cities where information security professionals and enthusiasts can share their knowledge with peers at a Security BSides conference. We’ve talked with BSidesZG organizer Ante Jurjevic to find out what’s in store for those who attend. How to tackle … More →
newswww.helpnetsecurity.comJan 29, 2023, 9:30 AM Introduction The recent VMware VMSA describes four new CVEs affecting VMware vRealize Log Insight. Three of these CVEs can be combined to give an attacker remote code execution as root. This vulnerability is exploitable in the default configuration for VMware vRealize Log Insight. CVE-2022-31704: VMware vRealize Log Insight broken access control Vulnerability CVE-2022-31711: VMware vRealize […]
exploithorizon3.aiJan 27, 2023, 7:19 PM- Critical VMware vRealize Log Insight flaws patched (CVE-2022-31706, CVE-2022-31704)Help Net Security
VMware has fixed two critical (CVE-2022-31706, CVE-2022-31704) and two important (CVE-2022-31710, CVE-2022-31711) security vulnerabilities in VMware vRealize Log Insight, its multi-cloud solution for centralized log management, operational visibility and intelligent analytics. Reported by Trend Micro’s Zero Day Initiative, none of the flaws are currently exploited by attackers in the wild, but given threat actors’ predilection for targeting widely used VMware solutions, fixing these sooner rather than later is a good idea. About the vulnerabilities CVE-2022-31706 … More →
newswww.helpnetsecurity.comJan 25, 2023, 11:01 AM A critical vulnerability in VMware vRealize Log Insight appliance can allow an unauthenticated attacker to take full control of a target system. VMware addressed multiple vulnerabilities, tracked as CVE-2022-31706, CVE-2022-31704, CVE-2022-31710, and CVE-2022-31711, in its vRealize Log Insight appliance. VRealize Log Insight is a log collection and analytics virtual appliance that enables administrators to collect, view, […]
newssecurityaffairs.comJan 24, 2023, 11:25 PM- VMware Plugs Critical Code Execution FlawsSecurityWeek
VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.
newswww.securityweek.comJan 24, 2023, 8:38 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-31703CVSS 7.5 · High
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance whic…
- CVE-2016-5332CVSS 5.3 · Medium
Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.
- CVE-2026-19942CVSS 8.1 · High
The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient…
- CVE-2026-73974CVSS 5.5 · Medium
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper acro…
- CVE-2026-73973CVSS 5.5 · Medium
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --fi…
- CVE-2026-52875CVSS 8.4 · High
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes sett…