CVE-2023-20868: Broadcom VMware Nsx-T Data Center

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

NSX-T contains a reflected cross-site scripting vulnerability due to a lack of input validation. A remote attacker can inject HTML or JavaScript to redirect to malicious pages.

Affected products

  • Broadcom VMware Nsx-T Data Center: from 3.2.0, before 3.2.3 (fixed in 3.2.3)

Published 2023-05-26. Last modified 2026-06-17.