/Vulnerability Library

VMWare Cloud Foundation NSX-V - XML External Entity (XXE)

CVE-2022-31678
Verified

Description

VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.

Severity

Critical

CVSS Score

9.1

Exploit Probability

8%

Affected Product

cloud_foundation

Published Date

January 22, 2026

Template Author

daffainfo

CVE-2022-31678.yaml
9.1Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVE ID:
cve-2022-31678
CWE ID:
cwe-611

References

https://srcincite.io/advisories/src-2022-0022/https://www.vmware.com/security/advisories/VMSA-2022-0027.htmlhttps://nvd.nist.gov/vuln/detail/cve-2022-31678

Remediation Steps

Update to the latest version of VMware Cloud Foundation with patched NSX-V component.