CVE-2025-41251: Weak password recovery vulnerability
VMware NSX contains a weak password recovery mechanism vulnerability. An unauthenticated malicious actor may exploit this to enumerate valid usernames, potentially enabling brute-force attacks.
Impact: Username enumeration → credential brute force risk. Attack Vector: Remote, unauthenticated. Severity: Important. CVSSv3: 8.1 (High).
Acknowledgments: Reported by the National Security Agency.
Affected Products:VMware NSX 9.x.x.x, 4.2.x, 4.1.x, 4.0.x
NSX-T 3.x VMware Cloud Foundation (with NSX) 5.x, 4.5.x
Fixed Versions: NSX 9.0.1.0; 4.2.2.2/4.2.3.1 http://4.2.2.2/4.2.3.1 ; 4.1.2.7; NSX-T 3.2.4.3; CCF async patch (KB88287). Workarounds: None.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41251?
CVE-2025-41251 is classified as a medium severity vulnerability due to its potential for username enumeration and subsequent brute-force attacks.
How do I fix CVE-2025-41251?
To fix CVE-2025-41251, update VMware NSX and VMware NSX-T to the latest patched versions provided by VMware.
What systems are affected by CVE-2025-41251?
CVE-2025-41251 affects VMware NSX versions from 4.0.0 to 9.x.x.x, VMware NSX-T starting from version 3.x, and VMware Cloud Foundation versions between 4.0.0 and 5.x.
Can CVE-2025-41251 be exploited remotely?
Yes, CVE-2025-41251 can be exploited remotely by an unauthenticated actor to enumerate valid usernames.
What risk does CVE-2025-41251 pose to users?
CVE-2025-41251 poses a risk of credential brute-force attacks due to the vulnerability in the password recovery mechanism.