Known vulnerabilities in NSX Data Center for vSphere 6.4.12

Vendor: Broadcom
Version: 6.4.12
Software CPE: cpe:2.3:a:broadcom:nsx_data_center_for_vsphere:*:*:*:*:*:*:*:*
Total vulnerabilities: 4
Public exploits: 2
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting NSX Data Center for vSphere version 6.4.12 NSX Data Center for vSphere 6.4.12 is affected by 4 vulnerabilities: 2 critical, 1 medium, 1 low Critical High Medium Low

Vulnerabilities (4)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU68721 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2022-31678
CWE-611 Medium
No
No
6.4.14 25.10.2022 SB2022102568
#VU68720 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-39144
CWE-94 Critical
Public exploit available
Exploited
6.4.14 25.10.2022 SB2021082322
SB2022102568
SB2023031801
and 17 more
#VU60627 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-22945
CWE-78 Low
No
No
6.4.13 15.02.2022 SB2022021516
#VU58816 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-44228
CWE-94 Critical
Public exploit available
Exploited
6.4.12 10.12.2021 SB2021121003
SB2021121101
SB2021121201
and 338 more