VMware NSX Username Enumeration Vulnerability
Vulnerability
A username enumeration vulnerability has been identified in VMware NSX. This vulnerability allows an unauthenticated malicious actor to enumerate valid usernames, which could lead to unauthorized access attempts. The issue is present in several versions of VMware NSX, including NSX 9.x.x.x, 4.2.x, 4.1.x, 4.0.x, NSX-T 3.x, and VMware Cloud Foundation (with NSX) 5.x and 4.5.x.
Impact
Exploitation of this vulnerability could facilitate unauthorized access by allowing attackers to identify valid usernames.
Remediation
Users can upgrade to NSX 9.0.1.0, 4.2.2.2, 4.2.3.1, 4.1.2.7, NSX-T 3.2.4.3, or apply the CCF async patch (KB88287).
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
