← Back to CVE List
CVE-2025-22244NVD
Vulnerability Summary
VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the gateway firewall due to improper input validation.
CVSS v3.1 Base Metrics — Score 6.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- Broadcom Vmware Nsx >= 3.2 and < 4.1.2.6
- Broadcom Vmware Nsx >= 4.2.1 and < 4.2.1.4
- Broadcom Vmware Nsx
- Vmware Cloud Foundation >= 4.5 and <= 5.2.1.2
- Vmware Telco Cloud Infrastructure >= 2.2 and <= 3.0
- Vmware Telco Cloud Platform >= 3.0 and <= 5.0
- Broadcom Vmware Nsx 4.1.2.6
- Broadcom Vmware Nsx 4.2.1.4