CVE-2022-31678 is a critical XML External Entity (XXE) vulnerability affecting VMware Cloud Foundation (VCF) 3.x instances with NSX-V deployed. This flaw allows an unauthenticated attacker to remotely trigger a denial-of-service condition or achieve unintended information disclosure. With a CVSS score of 9.1 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk. While not currently in CISA's KEV catalog, Nuclei templates exist for detection, and there is substantial community discussion and media coverage, including reports of ongoing exploitation against an end-of-life product.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.11CPE matchmatch criteria | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* | ||
< 6.4.14CPE matchmatch criteria | cpe:2.3:a:vmware:nsx_data_center:*:*:*:*:*:vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.