6.9

CVE-2025-22244

Media report

VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
BroadcomVmware Nsx Version >= 3.2 < 4.1.2.6
BroadcomVmware Nsx Version >= 4.2.1 < 4.2.1.4
BroadcomVmware Nsx Version4.2.2
VMwareCloud Foundation Version >= 4.5 <= 5.2.1.2
VMwareTelco Cloud Infrastructure Version >= 2.2 <= 3.0
VMwareTelco Cloud Platform Version >= 3.0 <= 5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.189
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
security@vmware.com 6.9 1.7 4.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.