Cyber Security News

VMware vCenter and NSX Vulnerabilities Let Attackers Enumerate Valid Usernames

VMware has disclosed critical security vulnerabilities in vCenter Server and NSX platforms that could allow attackers to enumerate valid usernames and manipulate system notifications. 

The vulnerabilities, tracked as CVE-2025-41250, CVE-2025-41251, and CVE-2025-41252, affect multiple VMware products, including Cloud Foundation, vSphere Foundation, NSX, NSX-T, and Telco Cloud platforms.

Broadcom, which acquired VMware, released a security advisory on September 29, 2025, rating the vulnerabilities with CVSS base scores ranging from 7.5 to 8.5, classifying them as “Important” severity. 

The National Security Agency (NSA) reported two of the three vulnerabilities, highlighting their potential national security implications.

vCenter SMTP Header Injection Vulnerability

The first vulnerability, CVE-2025-41250, is an SMTP header injection flaw in VMware vCenter Server with a CVSS score of 8.5. 

This vulnerability enables malicious actors with non-administrative privileges who have permission to create scheduled tasks to manipulate notification emails sent for those tasks.

The attack vector requires authenticated access to vCenter with task creation permissions. By exploiting SMTP header injection techniques, attackers can modify email headers, potentially redirecting notifications, inserting malicious content, or bypassing email security filters. 

This could lead to social engineering attacks, credential harvesting, or unauthorized disclosure of information through manipulated email communications.

Affected products include vCenter Server versions 7.0, 8.0, and 9.x across various VMware Cloud Foundation and vSphere Foundation deployments. 

The vulnerability impacts VMware Telco Cloud Platform versions 2.x through 5.x and Telco Cloud Infrastructure versions 2.x and 3.x.

Per von Zweigbergk receives acknowledgment for responsibly disclosing this vulnerability to Broadcom. No workarounds are available, requiring organizations to apply the provided security patches immediately.

NSX Username Enumeration Vulnerabilities

Two separate username enumeration vulnerabilities affect NSX platforms, creating pathways for reconnaissance attacks. 

CVE-2025-41251, with a CVSS score of 8.1, represents a weak password recovery mechanism vulnerability allowing unauthenticated attackers to enumerate valid usernames through password recovery processes.

CVE-2025-41252, scoring 7.5 on the CVSS scale, is a direct username enumeration vulnerability that permits unauthenticated malicious actors to identify valid usernames without requiring authentication. 

Both vulnerabilities can serve as reconnaissance tools for subsequent brute-force attacks or targeted credential stuffing campaigns.

Username enumeration attacks typically exploit differences in application responses when processing valid versus invalid usernames. 

Attackers can analyze response times, error messages, HTTP status codes, or other behavioral patterns to determine which usernames exist in the system. 

This information becomes valuable for password spraying attacks, social engineering campaigns, or targeted phishing attempts.

The NSX vulnerabilities affect VMware NSX versions 4.0.x through 4.2.x, NSX-T version 3.x, and NSX components within Cloud Foundation and Telco Cloud platforms. 

Organizations running these platforms face immediate exposure to reconnaissance attacks that could facilitate broader compromise attempts.

Security patches are available through various fixed versions, including NSX 4.2.2.2, 4.2.3.1, 4.1.2.7, and NSX-T 3.2.4.3. 

CVETitleCVSS 3.1 ScoreSeverity
CVE-2025-41250vCenter SMTP Header Injection Vulnerability8.5Important
CVE-2025-41251NSX Weak Password Recovery Mechanism Vulnerability8.1Important
CVE-2025-41252NSX Username Enumeration Vulnerability7.5Important

VMware Cloud Foundation users should implement asynchronous patching procedures documented in KB88287. Meanwhile, Telco Cloud Platform and Infrastructure users should refer to KB411518 for update guidance.

The NSA’s involvement in reporting these vulnerabilities underscores their significance for enterprise and government environments where VMware infrastructure provides critical virtualization and networking services. 

Broadcom has already released patches that organizations should prioritize to address these vulnerabilities, as username enumeration could enable more sophisticated attack campaigns targeting virtualized infrastructure.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Florence Nightingale

Florence Nightingale is a senior security and privacy reporter, covering data breaches, cybercrime, malware, and data leaks from cyber space daily.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago