VMware Product Security Update Advisory

VMware Product Security Update Advisory

Overview

Security updates addressing vulnerabilities in VMware products have been released. The affected products are VMware NSX, VMware Cloud Foundation, VMware Telco Cloud Infrastructure, and VMware Telco Cloud Platform.

Resolved Vulnerabilities

  • CVE-2025-22243.
  • CVE-2025-22244.
  • CVE-2025-22245.

All three vulnerabilities are stored cross-site scripting (stored XSS) vulnerabilities in VMware NSX (a vulnerability where malicious scripts are stored on a web page and can later be executed by a user).

Affected Products and Versions

  • VMware NSX 4.2.x.
  • VMware NSX 4.2.1.x.
  • VMware NSX 4.1.x, 4.0.x.
  • NSX-T 3.2.x.
  • VMware Cloud Foundation 5.2.x.
  • VMware Cloud Foundation 5.1.x, 5.0.x.
  • VMware Cloud Foundation 4.5.x.
  • VMware Telco Cloud Infrastructure 3.x, 2.x.
  • VMware Telco Cloud Platform 5.x, 4.x, 3.x, 2.x.

Patch Information

Vulnerability Patches have been released in the latest updates. The recommended patch versions are as follows:

  • VMware NSX 4.2.2.1.
  • VMware NSX 4.2.1.4.
  • VMware NSX 4.1.2.6.
  • NSX-T 3.2.4.2.
  • VMware Cloud Foundation requires the application of patches NSX 4.2.2.1, NSX 4.1.2.6, and NSX 3.2.4.2.
  • VMware Telco Cloud Infrastructure and VMware Telco Cloud Platform require patches as outlined on the reference site.

Reference

  • VMSA-2025-0012: VMware NSX updates address multiple vulnerabilities.
  • Broadcom has released advisory documents regarding CVE-2025-22243, CVE-2025-22244, and CVE-2025-22245.