vmware-vcenter-attack
Fail
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides explicit exploit templates and payloads for Remote Code Execution (RCE), specifically targeting Server-Side Template Injection (SSTI) vulnerabilities in Workspace ONE Access (CVE-2022-22954).
- [COMMAND_EXECUTION]: Orchestrates automated command sequences for active exploitation, including probes for unauthenticated arbitrary file upload vulnerabilities (CVE-2021-21972) and directory traversal.
- [DATA_EXFILTRATION]: Details specific methods and commands for the unauthorized extraction of sensitive information, including Virtual Machine Disks (VMDK), snapshots, and credentials stored in cloud-init configuration files from remote datastores.
- [CREDENTIALS_UNSAFE]: Hardcodes a reference table of default administrative credentials for various VMware products (e.g., vCenter, Aria, ESXi) intended for use in unauthorized access attempts.
- [PROMPT_INJECTION]: The skill lacks sanitization for the user-supplied 'TARGET' variable, which is directly interpolated into shell commands. This represents a vulnerability surface for indirect prompt injection where a malicious target environment could influence agent behavior through banner content or metadata.
Recommendations
- AI detected serious security threats
Audit Metadata