Advisory 2025-2004 - VMware Cloud Foundation, vSphere, vCenter Server and NSX: Multiple Vulnerabilities
The CTI portal is available at the following address: https://cti-portal.telekom.net/advisories/2025-2004
Date
2025-09-30
State
2025-09-30
Risk*
Damage: MEDIUM
Attack Probability: MEDIUM-HIGH
Attack
An attacker can exploit multiple vulnerabilities in VMware Cloud Foundation, VMware vSphere, VMware vCenter Server and VMware NSX in order to manipulate files and to disclose valid usernames, potentially enabling brute-force attacks and unauthorized access.
* The probability of an attack is determined by the attacker's motivation, the necessary expend and the possibilities for an attack. The damage probability is determined by the expend needed to resolute the attack and probable indirecte consequences of an attack for business processes. Telekom Security assumes worst case scenarios.
Copyright © 1999-2025 Deutsche Telekom Security GmbH. All rights reserved. Reproduction and distribution of this publication in any form - even in parts - without prior written permission is forbidden.
The information contained herein has been obtained from sources believed to be reliable and trusted or have been verified. Telekom Security can take liability for completeness, accuracy and correctness only in so far, as gross negligence or intention create liability. Any liability beyond it, in particular possible damages resulting from using or non-usability of the information contained herein, is excluded.