CVE-2022-22954
KEV RANSOMWAREHIGH 10.0EPSS 100.0%
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-04-14, used in ransomware campaigns
- Nuclei
- critical · CWE-94
- Published
- 2022-04-11
- Updated
- 2025-10-21
Proof-of-concept exploits (32)
- http://packetstormsecurity.com/files/166935/VMware-Workspace-ONE-Access-Template-Injectio…
- 1SeaMy/CVE-2022-229540★ · 2024-03-27
- 24-2021/EXP-POC26★ · 2023-01-11
- Chocapikk/CVE-2022-229544★ · 2022-06-01
- DrorDvash/CVE-2022-22954_VMware_PoC10★ · 2022-04-12
- Jun-5heng/CVE-2022-229540★ · 2022-04-19
- MLX15/CVE-2022-229544★ · 2022-04-15
- MSeymenD/CVE-2022-22954-Testi1★ · 2022-04-12
- Vulnmachines/VMWare_CVE-2022-2295411★ · 2022-04-11
- amit-pathak009/CVE-2022-229540★ · 2022-06-02
- amit-pathak009/CVE-2022-22954-PoC0★ · 2022-06-01
- aniqfakhrul/CVE-2022-229544★ · 2022-05-27
- arzuozkan/CVE-2022-229540★ · 2022-06-11
- axingde/CVE-2022-22954-POC2★ · 2022-04-15
- b4dboy17/CVE-2022-229545★ · 2022-06-03
- badboy-sft/CVE-2022-229545★ · 2022-06-03
- bewhale/CVE-2022-2295468★ · 2022-04-26
- chaosec2021/EXP-POC26★ · 2023-01-11
- corelight/cve-2022-229541★ · 2024-10-25
- emilyastranova/VMware-CVE-2022-22954-Command-Injector1★ · 2022-04-15
- jax7sec/CVE-2022-2295412★ · 2022-04-15
- lucksec/VMware-CVE-2022-229540★ · 2022-04-12
- mamba-2021/EXP-POC26★ · 2023-01-11
- mhurts/CVE-2022-22954-POC0★ · 2022-04-15
- nguyenv1nK/CVE-2022-229540★ · 2022-05-05
- orwagodfather/CVE-2022-229548★ · 2022-06-03
- secfb/CVE-2022-229540★ · 2022-06-01
- sherlocksecurity/VMware-CVE-2022-22954279★ · 2022-04-13
- tunelko/CVE-2022-22954-PoC16★ · 2024-02-13
- tyleraharrison/VMware-CVE-2022-22954-Command-Injector1★ · 2022-04-15
- zidanfanshao/vcenter_tools70★ · 2024-11-17
- nieldk/VMware-CVE-2022-22954