VMware NSX Username Enumeration Vulnerability

Vulnerability

A username enumeration vulnerability has been identified in VMware NSX. This vulnerability allows an unauthenticated malicious actor to enumerate valid usernames, which could lead to unauthorized access attempts. The issue is present in several versions of VMware NSX, including NSX 9.x.x.x, 4.2.x, 4.1.x, 4.0.x, NSX-T 3.x, and VMware Cloud Foundation (with NSX) 5.x and 4.5.x.

Impact

Exploitation of this vulnerability could facilitate unauthorized access by allowing attackers to identify valid usernames.

Remediation

Users can upgrade to NSX 9.0.1.0, 4.2.2.2, 4.2.3.1, 4.1.2.7, NSX-T 3.2.4.3, or apply the CCF async patch (KB88287).

Added: Sep 29, 2025, 7:23 PM
Updated: Sep 29, 2025, 7:41 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.2
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.