Broadcom Issues Patches for VMware NSX and vCenter Security Flaws
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-4006 | Command Injection in VMware Workspace ONE Access and Identity Manager CVE-2020-4006 is a command injection flaw (CWE-78, CVSS 3.1 9.1) in the admin consoles of VMware Workspace ONE Access, Workspace ONE Access Connector, VMware Identity Manager, and VMware Identity Manager Connector, with the affected components also shipped inside VMware Cloud Foundation and vRealize Suite Lifecycle Manager. An attacker who gains privileged access to an admin console, which is typically reachable over the network, can inject and run arbitrary commands on the appliance, achieving full compromise of the host with high confidentiality, integrity, and availability impact and a changed scope. Organizations running the affected identity products are exposed, especially where the admin console is internet-facing or reachable from untrusted networks. The bug was actively exploited by Russian state-sponsored (SVR/APT29) actors against unpatched deployments, prompting a CISA emergency directive, NSA and FBI joint warnings, and inclusion in the KEV catalog; EPSS estimates a 17.3% probability of exploitation within 30 days, and no public proof-of-concept is known. Do: Apply the patches VMware released in its November 2020 advisory (VMSA-2020-0027) for all affected products, connectors, and any Cloud Foundation or vRealize Suite Lifecycle Manager deployments that embed the components — this is a KEV-required action. As an interim mitigation, restrict network access to the admin console (typically port 8443) to trusted users and networks only. Review admin-console and system logs for signs of command injection or SVR/APT29 activity, since the bug was exploited in the wild by Russian state-sponsored actors. | 9.1 | 17% | KEV |
| largetens of thousands of enterprise identity-appliance deployments, with likely several thousand admin consoles internet-exposed | |
| CVE-2025-41244 | Local Privilege Escalation in VMware Aria Operations and VMware Tools CVE-2025-41244 is a local privilege escalation flaw (CWE-267, improper privilege management) in Broadcom's VMware Aria Operations and VMware Tools, arising from privileged operations performed in an unsafe manner. To exploit it, a malicious actor with non-administrative privileges must already have local access to a virtual machine that runs VMware Tools and is managed by Aria Operations with SDMP enabled, at which point they can escalate to root on that same VM. Successful exploitation yields full root-level control (high confidentiality, integrity, and availability impact per the 7.8 CVSS score) on affected guest VMs. Organizations running VMware Aria Operations-managed estates with VMware Tools or Open VM Tools on guests, including VMware Cloud Foundation, Cloud Foundation Operations, Telco Cloud, and Debian-packaged Tools deployments, are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-30, and news reports attribute exploitation to a China-linked actor, with EPSS estimating an 8.4% chance of exploitation within 30 days (95th percentile). Do: Apply the Broadcom patches for CVE-2025-41244 per the vendor advisory to Aria Operations and update VMware Tools/Open VM Tools on all managed guests, including bundled components in VMware Cloud Foundation, Cloud Foundation Operations, and Telco Cloud products; follow CISA KEV/BOD 22-01 requirements (patch per vendor instructions or discontinue use for cloud services). As interim mitigation, restrict non-administrative local access on Aria Operations-managed VMs and review whether SDMP is enabled, prioritizing internet-adjacent and high-value guests; Debian users should track the Debian advisory for updated open-vm-tools packages. | 7.8 | 8% | KEV PoC |
| massmillions of guest VMs run VMware Tools/Open VM Tools; the subset managed by Aria Operations with SDMP enabled is plausibly in the hundreds of thousands of VMs… | |
| CVE-2025-41245 | VMware Aria Operations contains an information disclosure vulnerability. VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations. NVD description · AI analysis pending | 4.9 | <1% | — | — | ||
| CVE-2025-41246 | VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. VMware Tools for Windows contains an improper authorisation vulnerability due to the way it handles user access controls. A malicious actor with non-administrative privileges on a guest VM, who is already authenticated through vCenter or ESX may exploit this issue to access other guest VMs. Successful exploitation requires knowledge of credentials of the targeted VMs and vCenter or ESX. NVD description · AI analysis pending | 7.6 | <1% | — | — | ||
| CVE-2025-41250 | VMware vCenter contains an SMTP header injection vulnerability. VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on vCenter who has permission to create scheduled tasks may be able to manipulate the notification emails sent for scheduled tasks. NVD description · AI analysis pending | 8.5 | <1% | — | — | ||
| CVE-2025-41251 | VMware NSX contains a weak password recovery mechanism vulnerability. VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 8.1 (High). Acknowledgments: Reported by the National Security Agency. Affected Products:VMware NSX 9.x.x.x, 4.2.x, 4.1.x, 4.0.x NSX-T 3.x VMware Cloud Foundation (with NSX) 5.x, 4.5.x Fixed Versions: NSX 9.0.1.0; 4.2.2.2/4.2.3.1 http://4.2.2.2/4.2.3.1 ; 4.1.2.7; NSX-T 3.2.4.3; CCF async patch (KB88287). Workarounds: None. NVD description · AI analysis pending | 8.1 | <1% | — | — | ||
| CVE-2025-41252 | Description: VMware NSX contains a username enumeration vulnerability. Description: VMware NSX contains a username enumeration vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially leading to unauthorized access attempts. Impact: Username enumeration → facilitates unauthorized access. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 7.5 (High). Acknowledgments: Reported by the National Security Agency. Affected Products: * VMware NSX 9.x.x.x, 4.2.x, 4.1.x, 4.0.x * NSX-T 3.x * VMware Cloud Foundation (with NSX) 5.x, 4.5.x Fixed Versions: * NSX 9.0.1.0; 4.2.2.2/4.2.3.1 http://4.2.2.2/4.2.3.1 ; 4.1.2.7; NSX-T 3.2.4.3; CCF async patch (KB88287). Workarounds: None. NVD description · AI analysis pending | 7.5 | <1% | — | — |
Full article482 words · extracted from infosecurity-magazine.com · click to collapse
A set of substantial security updates for VMware NSX and vCenter has been released by Broadcom, addressing multiple high-severity vulnerabilities that could expose enterprise systems to cyberattacks.
The flaws, disclosed in the latest VMware vCenter and NSX updates, address multiple vulnerabilities (CVE-2025-41250, CVE-2025-41251, CVE-2025-41252), that were reported by the US National Security Agency and independent security researchers.
They affect several Broadcom products, including VMware Cloud Foundation, NSX-T and VMware Telco Cloud Platform.
One of the most severe issues, tracked as CVE-2025-41250, is an SMTP header injection bug in vCenter. With a CVSSv3 base score of 8.5, it allows attackers with non-administrative privileges to modify email notifications associated with scheduled tasks. Broadcom said no workarounds are available and users should apply the fixed versions immediately.
Two other flaws in VMware NSX, CVE-2025-41251 and CVE-2025-41252, stem from weaknesses in the authentication process. Both enable unauthenticated attackers to enumerate valid usernames, a step that could support brute-force or unauthorized login attempts.
“Based on the information at hand, these vulnerabilities might be combined to create a viable attack path from unauthenticated reconnaissance to authenticated compromise,” said Mayuresh Dani, security research manager at Qualys Threat Research Unit.
“Once authenticated (considering limited privileges), threat actors will exploit the vCenter SMTP header injection to potentially redirect sensitive communication and escalate their privileges.”
The vulnerabilities are classified as “High” with CVSS scores ranging from 7.5 to 8.5. The weaknesses affect a wide span of VMware infrastructure solutions used in enterprise and telecom environments.
According to the Broadcom advisory, the following products are impacted:
-
VMware NSX
-
NSX-T
-
VMware Cloud Foundation
-
VMware vCenter Server
-
VMware Telco Cloud Platform
-
VMware Telco Cloud Infrastructure
“The two NSX bugs allow unauthenticated users to confirm which usernames exist on a system,” explained Jason Soroko, senior fellow at Sectigo.
“Even without direct code execution, these kinds of flaws are attractive building blocks that adversaries combine with weak or reused credentials to pivot deeper, which helps explain why an intelligence agency would flag them despite High, rather than Critical, ratings.”
Broader Disclosure
Alongside these patches, Broadcom also revealed three other vulnerabilities in VMware Aria Operations and VMware Tools.
These flaws (CVE-2025-41244, CVE-2025-41245, CVE-2025-41246) could allow attackers to escalate privileges to root, steal credentials or access guest VMs.
“The last time the NSA reported VMware vulnerabilities was when Russian state-sponsored actors were actively exploiting them,” Dani noted, referencing CVE-2020-4006.
“This suggests the agency may have intelligence indicating potential exploitation interest from nation-state actors.”
At the time of publication, Soroko clarified: “There is no public confirmation that the NSX username enumeration bugs or the vCenter SMTP header injection were exploited in the wild.”
Still, administrators are urged to update affected systems as soon as possible to mitigate risks. Fixed versions and documentation are available through Broadcom’s support site.
Image credit: CryptoFX / Shutterstock.com
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/broadcom-patches-vmware-nsx-vcenter/