Executive brief
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in its local web UI component. An unauthenticated attacker can exploit this to achieve remote code execution, though the component is disabled by default and requires a non-default configuration to be vulnerable.
Affected products
- VMware NSX SD-WAN Edge by VeloCloud prior to 3.1.0
Timeline
- 2018-06-11: disclosed: Initial NVD publication date
- 2018-06-11: advisory: VMSA-2018-0011 published by VMware
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: exploited: Confirmed as exploited in the wild per CISA KEV entry