CVE-2018-6961
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- February 14, 2018
- Published Date
- June 11, 2018
- Last Updated
- February 07, 2025
- Vendor
- VMware
- Product
- NSX SD-WAN by VeloCloud
- Description
- VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
CVSS Scores
CVSS v3.1
8.1 - HIGH
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC Information
- Exploitation
- active
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-03-25 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
r3dxpl0it/CVE-2018-6961
Type: github • Created: 2019-02-08 13:00:35 UTC • Stars: 5
VMware NSX SD-WAN command injection vulnerability
bokanrb/CVE-2018-6961
Type: github • Created: 2018-09-12 19:44:15 UTC • Stars: 1
veloCloud VMWare - Vulnerability