Show plain JSON{"id": "CVE-2022-22983", "cveTags": [], "metrics": {"cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 5.9, "attackVector": "LOCAL", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 4.0, "exploitabilityScore": 1.5}]}, "published": "2022-08-10T20:15:30.457", "references": [{"url": "https://www.vmware.com/security/advisories/VMSA-2022-0023.html", "tags": ["Patch", "Vendor Advisory"], "source": "security@vmware.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-522"}]}], "descriptions": [{"lang": "en", "value": "VMware Workstation (16.x prior to 16.2.4) contains an unprotected storage of credentials vulnerability. A malicious actor with local user privileges to the victim machine may exploit this vulnerability leading to the disclosure of user passwords of the remote server connected through VMware Workstation."}, {"lang": "es", "value": "VMware Workstation (versiones 16.x anteriores a 16.2.4) contiene una vulnerabilidad de almacenamiento de credenciales sin protecci\u00f3n. Un actor malicioso con privilegios de usuario local en la m\u00e1quina v\u00edctima puede explotar esta vulnerabilidad conllevando a una divulgaci\u00f3n de contrase\u00f1as de usuario del servidor remoto conectado mediante VMware Workstation"}], "lastModified": "2022-08-15T20:47:19.057", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:vmware:workstation:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AD35B121-F46A-4A4F-877F-BA960BE8F536", "versionEndExcluding": "16.2.4", "versionStartIncluding": "16.0.0"}], "operator": "OR"}]}], "sourceIdentifier": "security@vmware.com"}