
🚨 CVE-2025-41251 : HIGH-SEVERITY INFO DISCLOSURE ALERT 🚨 @VMware A username enumeration vulnerability has been disclosed in VMware NSX, the core network virtualization and micro-segmentation platform protecting enterprise and critical infrastructure workloads. Risk Severity: High (CVSS 8.1, active exploitation, public exploit available, NSA-reported) Impact: • Unauthenticated enumeration of valid admin & service accounts • Targeted password spraying and credential stuffing • Accelerated initial access to NSX management plane • Increased risk of ransomware staging & lateral movement • Exposure of critical network control identities Root Cause: CWE-204 (Observable Response Discrepancy). VMware NSX’s password recovery workflow returns measurably different responses for valid vs. non-existent usernames, enabling attackers to infer account existence via timing and response analysis. Attackers can: • Probe password reset endpoints without authentication • Reliably enumerate administrative and automation accounts • Correlate usernames with enterprise directory structures • Precisely target follow-on authentication attacks • Prepare infrastructure-level compromises Are You Affected? Vulnerable: NSX 9.x, 4.2.x, 4.1.x, 4.0.x; NSX-T 3.x; VCF 5.x / 4.5.x Scope: NSX Manager & Policy Manager interfaces reachable from internal or untrusted networks Immediate Action Required: Update: Upgrade to fixed releases (NSX 9.0.0.1+, 4.2.4+, 4.1.6+, 4.0.8+; VCF 5.1.1+) Mitigation: Restrict NSX management access to dedicated management VLANs / jump hosts Audit: Hunt for rapid password recovery requests and follow-on auth failures Enumeration is the first domino in infrastructure takeovers. Patch now. 🛡️ #vmware #security #ostorlabCVE
Post summary
The advisory announces a high‑severity username enumeration flaw (CVE‑2025‑41251) in VMware NSX, highlights that active exploitation and a public exploit exist, and urges immediate patching and network segmentation to mitigate the risk.
