CVE-2024-38815: VMware Cloud Foundation

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

VMware NSX contains a content spoofing vulnerability.  An unauthenticated malicious actor may be able to craft a URL and redirect a victim to an attacker controlled domain leading to sensitive information disclosure.

Affected products

  • VMware Cloud Foundation
  • VMware Nsx: from 4.1.0, before 4.2.1 (fixed in 4.2.1)
  • VMware Nsx-T: from 3.2.0, before 3.2.4.1 (fixed in 3.2.4.1)

Published 2024-10-09. Last modified 2026-06-17.