⚠ Exploited in the wild
Exploitation observed in the wild. Not yet on CISA KEV.

CVE-2022-31678XML External Entity (XXE) Injection in Vmware Cloud Foundation

Severity
9.1CRITICALNVD
EPSS
86.0%
top 0.61%
CISA KEV
Not in KEV
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedOct 28

Description

VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-g3gp-3rff-x6qf: VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability2022-10-28
CVEList
CVE-2022-31678: VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability2022-10-28
VulnCheck
VMware cloud_foundation Improper Restriction of XML External Entity Reference2022

💥Exploits & PoCs

1
Nuclei
VMWare Cloud Foundation NSX-V - XML External Entity (XXE)

📋Vendor Advisories

1
VMware
VMware Cloud Foundation updates address multiple vulnerabilities.2022-10-25
CVE-2022-31678 — XML External Entity (XXE) Injection | cvebase