S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 15, 2025

CVE-2022-31704 Scanner

CVE-2022-31704 Scanner - Remote Code Execution (RCE) vulnerability in VMware vRealize Log Insight

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-31704
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
vRealize Log Insight (vRLI)by n/a
vRealize Log Insight 8.10.1 and prior
Updated Aug 22, 2026View on NVD →
Detail

VMware vRealize Log Insight is primarily used for log management by businesses and organizations, providing real-time insights and monitoring of infrastructure. It allows users to collect, analyze, and manage large volumes of log data, primarily for troubleshooting and auditing purposes. This software is commonly employed by IT departments across various industries, including finance, healthcare, and technology, to ensure system reliability and security. As part of the VMware suite, it integrates comfortably with other VMware products and enhances the management of virtual environments. The platform is widely used for its robust analytics and its capacity to process enormous log data sets, making it integral for data-driven decision-making. Its deployment aids organizations in maintaining compliance and safeguarding their IT environments from potential threats.

The vulnerability in question is a Remote Code Execution (RCE) flaw found within VMware vRealize Log Insight. This vulnerability allows an unauthenticated attacker to exploit improper access controls, potentially leading to the unwanted execution of code on targeted systems. The seriousness of this vulnerability stems from its ability to be remotely exploited without prior authentication, increasing its accessibility to malicious actors. If left unmitigated, this flaw can present significant security risks, leading to unauthorized control over affected systems. The issue has been assigned a critical severity rating due to the potential impact and ease of exploitation. Organizations using the affected versions are urged to remediate the risk promptly to avoid system compromise.

The vulnerability exploits VMware vRealize Log Insight by targeting a specific weakness in the access control mechanism, enabling unauthorized code injection. The attacker leverages this access to inject malicious code, which is then executed on the appliance hosting the software. The vulnerable endpoint is exposed to unauthenticated users, allowing them to manipulate sensitive files. The issue lies in the improper validation of access permissions, enabling the bypassing of normal security checks. Successful exploitation does not require user interaction, which lowers the barrier for potential attackers. Consequently, attackers can gain unauthorized access to execute arbitrary commands remotely on the affected systems.

Exploitation of this vulnerability can lead to severe repercussions, including the complete compromise of the affected VMware vRealize Log Insight system. Potential consequences include unauthorized access to sensitive data, disruption of service, or further infiltration into connected networks. Attackers may deploy additional malicious payloads or create a persistent presence within the compromised infrastructure. The gains from exploiting this flaw enable attackers to manipulate system configurations and data undetected, posing ongoing and widespread risks to organizational operations. The critical nature of this vulnerability necessitates immediate attention to prevent exploitation.

REFERENCES

Solution Advice
  • Update VMware vRealize Log Insight to version 8.10.2 or later to mitigate the vulnerability.
  • Ensure proper network segmentation to limit exposure of appliances running VMware vRealize Log Insight.
  • Regularly audit and review access permissions and security configurations on systems.
  • Implement network intrusion detection and prevention systems to identify and block exploit attempts.
  • Conduct regular security training for all IT personnel to recognize and respond to security incidents.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.