Multiple vulnerabilities threaten VMware Cloud Foundation
The VMware Cloud Foundation cloud solution is vulnerable. Attackers can gain unauthorized access to data and services.
(Image: Tatiana Popova/Shutterstock.com)
Broadcom's developers have closed a total of three software vulnerabilities in VMware Cloud Foundation. Attackers can use these to launch attacks.
Danger from attacks
According to a warning message, the vulnerabilities (CVE-2025-41229, CVE-2025-41230, CVE-2025-41231) are classified with a "high" threat level. If attackers successfully exploit the vulnerabilities, they can access sensitive information or internal services in the network via port 443, for example.
Videos by heise
So far, there have been no reports of attacks. The developers assure us that they have closed the gaps in versions 5.2.1.2 and 4.5.x KB398008.
Most recently, security vulnerabilities in VMware Aria Automation made the headlines. Here, too, attackers were able to gain unauthorized access to areas that were actually sealed off.
(des)