CVE-2018-6961
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- February 14, 2018
- Published Date
- June 11, 2018
- Last Updated
- February 07, 2025
- Vendor
- VMware
- Product
- NSX SD-WAN by VeloCloud
- Description
- VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
- Tags
- Exploitation
- active
- Technical Impact
- total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-03-25 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
r3dxpl0it/CVE-2018-6961
Type: github • Created: 2019-02-08 13:00:35 UTC • Stars: 5
bokanrb/CVE-2018-6961
Type: github • Created: 2018-09-12 19:44:15 UTC • Stars: 1
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Added to KEVIntel