Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-20868

Disclosure Date: May 26, 2023 (last updated October 08, 2023)
NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.
Attacker Value
Unknown

CVE-2022-31678

Disclosure Date: October 28, 2022 (last updated February 24, 2025)
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Attacker Value
Unknown

CVE-2022-22945

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.
Attacker Value
Unknown

CVE-2021-21981

Disclosure Date: April 19, 2021 (last updated February 22, 2025)
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment. Successful exploitation of this issue may allow attackers with local guest user account to assign privileges higher than their own permission level.
Attacker Value
Unknown

CVE-2020-3993

Disclosure Date: October 20, 2020 (last updated November 28, 2024)
VMware NSX-T (3.x before 3.0.2, 2.5.x before 2.5.2.2.0) contains a security vulnerability that exists in the way it allows a KVM host to download and install packages from NSX manager. A malicious actor with MITM positioning may be able to exploit this issue to compromise the transport node.