PT-2025-17430 · Unknown · Ova Based Connect

Published

2025-04-21

·

Updated

2025-04-21

·

CVE-2025-3837

CVSS v4.0

6.1

Medium

VectorAV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions VMware End of Life OVA Connect versions prior to the end of support in January 2024
Description An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component, which is deployed for installation purposes in the customer's internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload, which could lead to a remote code execution on the infrastructure hosting this component.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-3837

Affected Products

Ova Based Connect