VMware vCenter and NSX Vulnerabilities Let Attackers Enumerate Valid Usernames
VMware has identified significant security vulnerabilities in its vCenter Server and NSX platforms. These vulnerabilities, designated as CVE-2025-41250, CVE-2025-41251, and CVE-2025-41252, are present in various VMware products, including Cloud…
VMware has identified significant security vulnerabilities in its vCenter Server and NSX platforms. These vulnerabilities, designated as CVE-2025-41250, CVE-2025-41251, and CVE-2025-41252, are present in various VMware products, including Cloud Foundation, vSphere Foundation, NSX, NSX-T, and Telco Cloud platforms.
Broadcom, the parent company of VMware, issued a security advisory on Fri, Sep 29, 2025, assessing these vulnerabilities with CVSS base scores from 7.5 to 8.5, categorizing them as "Important."
The National Security Agency (NSA) has reported two of these vulnerabilities due to their potential national security impact.
vCenter SMTP Header Injection Vulnerability
The vulnerability, CVE-2025-41250, is an SMTP header injection issue in VMware vCenter Server with a CVSS score of 8.5. This flaw allows attackers with non-administrative permissions and the ability to create scheduled tasks to alter notification emails sent for those tasks.
The attack requires authenticated access to vCenter with task creation permissions. By leveraging SMTP header injection techniques, attackers can modify email headers, potentially redirecting notifications or inserting malicious content.
This vulnerability affects vCenter Server versions 7.0, 8.0, and 9.x within VMware Cloud Foundation and vSphere Foundation deployments. It also impacts VMware Telco Cloud Platform versions 2.x through 5.x and Telco Cloud Infrastructure versions 2.x and 3.x. No workarounds exist, and security patches should be applied immediately.
VMware has identified significant security vulnerabilities in its vCenter Server and NSX platforms.
NSX Username Enumeration Vulnerabilities
Two username enumeration vulnerabilities impact NSX platforms. CVE-2025-41251, with a CVSS score of 8.1, involves a weak password recovery mechanism that allows unauthenticated attackers to enumerate valid usernames. CVE-2025-41252, scoring 7.5, enables attackers to identify valid usernames without authentication.
These vulnerabilities can facilitate reconnaissance attacks, potentially leading to brute-force attacks or credential stuffing campaigns. They affect VMware NSX versions 4.0.x through 4.2.x, NSX-T version 3.x, and NSX components within Cloud Foundation and Telco Cloud platforms.
Security patches are available for NSX 4.2.2.2, 4.2.3.1, 4.1.2.7, and NSX-T 3.2.4.3.
CVE Title CVSS 3.1 Score Severity
CVE-2025-41250 vCenter SMTP Header Injection Vulnerability 8.5 Important
CVE-2025-41251 NSX Weak Password Recovery Mechanism Vulnerability 8.1 Important
CVE-2025-41252 NSX Username Enumeration Vulnerability 7.5 Important
VMware Cloud Foundation users should follow asynchronous patching procedures as outlined in KB88287. Users of Telco Cloud Platform and Infrastructure are advised to refer to KB411518 for update guidance.
The involvement of the NSA in reporting these vulnerabilities highlights their critical importance for enterprise and government environments utilizing VMware infrastructure for virtualization and networking services. Broadcom has released patches that organizations should prioritize to mitigate these vulnerabilities and prevent potential sophisticated attack campaigns.
Based on reporting by Cyber Security News.
