VMWare Cloud Foundation NSX-V - XML External Entity (XXE)
CVE-2022-31678
Verified
Description
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
Severity
Critical
CVSS Score
9.1
Exploit Probability
8%
Affected Product
cloud_foundation
Published Date
January 22, 2026
Template Author
daffainfo
CVE-2022-31678.yaml
9.1Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
CVE ID:
cve-2022-31678
CWE ID:
cwe-611
Remediation Steps
Update to the latest version of VMware Cloud Foundation with patched NSX-V component.