Authenticated Command-Execution Vulnerability in vCenter Server by Broadcom
CVE-2025-41225
8.8HIGH
What is CVE-2025-41225?
The vCenter Server, developed by Broadcom, is susceptible to an authenticated command-execution vulnerability. This vulnerability allows an authorized user with permissions to create or modify alarms and execute script actions to potentially run arbitrary commands on the vCenter Server. If exploited, this could permit malicious actors to manipulate server functions or extract sensitive data, making it crucial for organizations to address this security issue promptly.
Affected Version(s)
Cloud Foundation 5.x, 4.5.x
Telco Cloud Infrastructure 3.x, 2.x
Telco Cloud Platform 5.x, 4.x, 3.x, 2.x