CVE-2024-38817: VMware Cloud Foundation
Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.
VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
Affected products
- VMware Cloud Foundation
- VMware Nsx: from 4.1.0, before 4.2.1 (fixed in 4.2.1)
- VMware Nsx-T: from 3.2.0, before 3.2.4.1 (fixed in 3.2.4.1)
Published 2024-10-09. Last modified 2026-06-17.