CVE-2025-41230

HIGH

VMware Cloud Foundation - Info Disclosure

Title source: llm
STIX 2.1

Description

VMware Cloud Foundation contains an information disclosure vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to gain access to sensitive information.

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 60.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
VMware/Cloud Foundation 4.5.x
VMware/Cloud Foundation 5.x - 5.2.1.2
Published May 20, 2025
Tracked Since Feb 18, 2026