CVE-2022-31678
published 2022-10-28CVE-2022-31678: VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit…
PriorityP276critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
8.02%
94.2th percentile
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | < 3.11 | 3.11 |
| vmware | nsx_data_center | < 6.4.14 | 6.4.14 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect XXE exploitation attempts against NSX-V by monitoring POST requests to /api/3.0/services/auth/token with Content-Type: application/xml containing DOCTYPE/ENTITY declarations. ↗
- →Successful XXE exploitation triggers an outbound HTTP callback with a Java User-Agent; monitor for unexpected outbound HTTP connections from NSX-V appliances with 'User-Agent: Java'. ↗
- →The vulnerable endpoint returns HTTP 403 with body containing 'Bad Username or Credentials presented' even when XXE payload is processed; use this response fingerprint to identify exploitation attempts. ↗
- →Identify exposed VMware NSX-V appliances by searching for the login page title 'VMware Appliance Management' on internet-facing assets (Shodan/FOFA). ↗
- →The vulnerability is unauthenticated and targets VCF 3.x instances with NSX-V deployed; prioritize scanning for these versions in your environment. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
vulncheck9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g3gp-3rff-x6qf: VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability
ghsa_unreviewed·2022-10-28
CVE-2022-31678 [CRITICAL] CWE-611 GHSA-g3gp-3rff-x6qf: VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
VulnCheck
VMware cloud_foundation Improper Restriction of XML External Entity Reference
vulncheck·2022·CVSS 9.1
CVE-2022-31678 [CRITICAL] VMware cloud_foundation Improper Restriction of XML External Entity Reference
VMware cloud_foundation Improper Restriction of XML External Entity Reference
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Affected: VMware cloud_foundation
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://lab.wallarm.com/vmware-nsx-manager-vulnerabilities-being-actively-exploited-in-the-wild/
VMware
VMware Cloud Foundation updates address multiple vulnerabilities.
vendor_vmware·2022-10-25·CVSS 8.5
CVE-2021-39144 [HIGH] VMware Cloud Foundation updates address multiple vulnerabilities.
VMSA-2022-0027: VMware Cloud Foundation updates address multiple vulnerabilities.
VMware Cloud Foundation contains a remote code execution vulnerability via XStream open source library. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.
CVEs: CVE-2021-39144, CVE-2022-31678
Affected products: VMware Cloud Foundation
No detection rules found.
Nuclei
VMWare Cloud Foundation NSX-V - XML External Entity (XXE)
nuclei·CVSS 9.1
CVE-2022-31678 [CRITICAL] VMWare Cloud Foundation NSX-V - XML External Entity (XXE)
VMWare Cloud Foundation NSX-V - XML External Entity (XXE)
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Template:
id: CVE-2022-31678
info:
name: VMWare Cloud Foundation NSX-V - XML External Entity (XXE)
author: daffainfo
severity: critical
description: |
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
impact: |
Attackers can cause denial-of-service or access sensitive information by expl
2022-10-28
Published
Exploited in the wild