CVE-2025-41251Patch

MEDIUMCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks. Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 8.1 (High). Acknowledgments: Reported by the National Security Agency. Affected Products:VMware NSX 9.x.x.x, 4.2.x, 4.1.x, 4.0.x NSX-T 3.x VMware Cloud Foundation (with NSX) 5.x, 4.5.x Fixed Versions: NSX 9.0.1.0; 4.2.2.2/4.2.3.1 http://4.2.2.2/4.2.3.1 ; 4.1.2.7; NSX-T 3.2.4.3; CCF async patch (KB88287). Workarounds: None.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-27: 1Active Exploitation · 2026-01-27: 1Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 101-27
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2025-41251 : HIGH-SEVERITY INFO DISCLOSURE ALERT 🚨 @VMware  A username enumeration vulnerability has been disclosed in VMware NSX, the core network virtualization and micro-segmentation platform protecting enterprise and critical infrastructure workloads. Risk Severity: High (CVSS 8.1, active exploitation, public exploit available, NSA-reported) Impact: • Unauthenticated enumeration of valid admin & service accounts • Targeted password spraying and credential stuffing • Accelerated initial access to NSX management plane • Increased risk of ransomware staging & lateral movement • Exposure of critical network control identities Root Cause: CWE-204 (Observable Response Discrepancy). VMware NSX’s password recovery workflow returns measurably different responses for valid vs. non-existent usernames, enabling attackers to infer account existence via timing and response analysis. Attackers can: • Probe password reset endpoints without authentication • Reliably enumerate administrative and automation accounts • Correlate usernames with enterprise directory structures • Precisely target follow-on authentication attacks • Prepare infrastructure-level compromises Are You Affected? Vulnerable: NSX 9.x, 4.2.x, 4.1.x, 4.0.x; NSX-T 3.x; VCF 5.x / 4.5.x Scope: NSX Manager & Policy Manager interfaces reachable from internal or untrusted networks Immediate Action Required: Update: Upgrade to fixed releases (NSX 9.0.0.1+, 4.2.4+, 4.1.6+, 4.0.8+; VCF 5.1.1+) Mitigation: Restrict NSX management access to dedicated management VLANs / jump hosts Audit: Hunt for rapid password recovery requests and follow-on auth failures Enumeration is the first domino in infrastructure takeovers. Patch now. 🛡️ #vmware #security #ostorlabCVE

    Post summary

    The advisory announces a high‑severity username enumeration flaw (CVE‑2025‑41251) in VMware NSX, highlights that active exploitation and a public exploit exist, and urges immediate patching and network segmentation to mitigate the risk.

    01030104
    582 followersView on X

Explore more