VMware Aria Ops Cred Disclosure via Info Leak
CVE-2025-41245 Published on September 29, 2025
VMware Aria Operations contains an information disclosure vulnerability. A malicious actor with non-administrative privileges in Aria Operations may exploit this vulnerability to disclose credentials of other users of Aria Operations.
Vulnerability Analysis
CVE-2025-41245 can be exploited with network access, and requires user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Insecure Default Initialization of Resource
The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
Products Associated with CVE-2025-41245
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-41245 are published in these products:
Affected Versions
VMware Aria Operations:- Version 8.18.x and below 8.18.5 is affected.
- Version 5.x and below 8.18.5 is affected.
- Version 4.x and below 8.18.5 is affected.
- Version 5.x and below 8.18.5 is affected.
- Version 4.x and below 8.18.5 is affected.
- Version 3.x and below 8.18.5 is affected.
- Version 2.x and below 8.18.5 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.