<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware Cloud Foundation</title>
  <link>https://cvedaily.com/pages/tags/vmware-cloud-foundation.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/vmware-cloud-foundation.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware Cloud Foundation</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:05 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-41252 – Description: VMware NSX contains a username enumeration vulnerability. An unauth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41252</guid>
    <pubDate>Mon, 29 Sep 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41252</strong></p>
  <p>Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts.   Impact: Username enumeration → facilitates unauthorized access.   Attack Vector: Remote, unauthenticated.   Severity: Important.   CVSSv3: 7.5 (High).   Acknowledgments: Reported by the Natio…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41251 – VMware NSX contains a weak password recovery mechanism vulnerability. An unauthe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41251</guid>
    <pubDate>Mon, 29 Sep 2025 19:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41251</strong></p>
  <p>VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks.  Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 8.1 (High).  Acknowledgments: Reported by the National Security Agency.  Af…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41231 – VMware Cloud Foundation contains a missing authorisation vulnerability. A malici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41231</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41231</guid>
    <pubDate>Tue, 20 May 2025 13:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41231</strong></p>
  <p>VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41231">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41230 – VMware Cloud Foundation contains an information disclosure vulnerability. A mali...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41230</guid>
    <pubDate>Tue, 20 May 2025 13:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41230</strong></p>
  <p>VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to gain access to sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41229 – VMware Cloud Foundation contains a directory traversal vulnerability. A maliciou...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41229</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41229</guid>
    <pubDate>Tue, 20 May 2025 13:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41229</strong></p>
  <p>VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41229">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31678 – VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31678</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31678</guid>
    <pubDate>Fri, 28 Oct 2022 02:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31678</strong></p>
  <p>VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31678">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22939 – VMware Cloud Foundation contains an information disclosure vulnerability due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22939</guid>
    <pubDate>Fri, 04 Feb 2022 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22939</strong></p>
  <p>VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in plaintext within one or more log files.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21973 – The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21973</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21973</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21973</strong></p>
  <p>The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 befor…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21973">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-21972 – The vSphere Client (HTML5) contains a remote code execution vulnerability in a v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21972</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21972</guid>
    <pubDate>Wed, 24 Feb 2021 17:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-21972</strong></p>
  <p>The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server. This affects VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Clo…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21972">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3999 – VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3999</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3999</guid>
    <pubDate>Mon, 21 Dec 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3999</strong></p>
  <p>VMware ESXi (7.0 prior to ESXi70U1c-17325551), VMware Workstation (16.x prior to 16.0 and 15.x prior to 15.5.7), VMware Fusion (12.x prior to 12.0 and 11.x prior to 11.5.7) and VMware Cloud Foundation contain a denial of service vulnerability due to improper input validation in GuestInfo. A malicious actor with normal user privilege access to a virtual machine can crash the virtual machine's vmx…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3999">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
