Authenticated Command-Execution Vulnerability in vCenter Server by Broadcom
CVE-2025-41225

8.8HIGH

Key Information:

Vendor

Vmware

Vendor
CVE Published:
20 May 2025

What is CVE-2025-41225?

The vCenter Server, developed by Broadcom, is susceptible to an authenticated command-execution vulnerability. This vulnerability allows an authorized user with permissions to create or modify alarms and execute script actions to potentially run arbitrary commands on the vCenter Server. If exploited, this could permit malicious actors to manipulate server functions or extract sensitive data, making it crucial for organizations to address this security issue promptly.

Affected Version(s)

Cloud Foundation 5.x, 4.5.x

Telco Cloud Infrastructure 3.x, 2.x

Telco Cloud Platform 5.x, 4.x, 3.x, 2.x

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-41225 : Authenticated Command-Execution Vulnerability in vCenter Server by Broadcom