Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-31678


VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.


Published

2022-10-28T02:15:17.267

Last Modified

2025-05-08T16:15:21.123

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.1 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-611
  • Type: Secondary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware cloud_foundation < 3.11 Yes
Application vmware nsx_data_center < 6.4.14 Yes

References