PT-2025-17430 · Unknown · Ova Based Connect
Published
2025-04-21
·
Updated
2025-04-21
·
CVE-2025-3837
CVSS v4.0
6.1
Medium
| Vector | AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
VMware End of Life OVA Connect versions prior to the end of support in January 2024
Description
An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component, which is deployed for installation purposes in the customer's internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload, which could lead to a remote code execution on the infrastructure hosting this component.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ova Based Connect