VYPR
Unrated severityNVD Advisory· Published May 20, 2025· Updated May 20, 2025

VMware Cloud Foundation Missing Authorisation Vulnerability

CVE-2025-41231

Description

VMware Cloud Foundation contains a missing authorisation vulnerability. A malicious actor with access to VMware Cloud Foundation appliance may be able to perform certain unauthorised actions and access limited sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A missing authorization vulnerability in VMware Cloud Foundation allows an authenticated appliance user to perform unauthorized actions and access limited sensitive information.

Vulnerability

VMware Cloud Foundation contains a missing authorization vulnerability (CVE-2025-41231). The flaw allows a malicious actor with access to the VMware Cloud Foundation appliance to perform certain unauthorized actions and access limited sensitive information. The specific component and exact conditions required to reach the vulnerable code path have not been disclosed in the advisory. Affected versions include VMware Cloud Foundation deployments prior to the updates specified in VMSA-2025-0009 [1].

Exploitation

An attacker must have access to the VMware Cloud Foundation appliance, implying a prior foothold or authenticated access. The advisory does not detail the precise steps or attack vector required to trigger the missing authorization. The vulnerability is distinct from CVE-2025-41229 (directory traversal) and CVE-2025-41230 (information disclosure), which require network access to port 443 [1].

Impact

Successful exploitation enables the attacker to perform actions that should be restricted and access limited sensitive information. The level of privilege achieved and the nature of the unauthorized actions are not fully described, but the CVSSv3 base score range for the advisory is 7.3-8.2, indicating high severity [1].

Mitigation

Broadcom (VMware) has released updates to remediate this vulnerability. The fixed versions are listed in the 'Fixed Version' column of the Response Matrix in VMSA-2025-0009 [1]. No workarounds are available. Affected users should apply the updates as soon as possible.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.