Junglewise Threat Intelligence

CVE-2018-6961: VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

CVE-2018-6961 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2022-03-25

Vendors: VMware.

Executive brief

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in its local web UI component. An unauthenticated attacker can exploit this to achieve remote code execution, though the component is disabled by default and requires a non-default configuration to be vulnerable.

Affected products

  • VMware NSX SD-WAN Edge by VeloCloud prior to 3.1.0

Timeline

  • 2018-06-11: disclosed: Initial NVD publication date
  • 2018-06-11: advisory: VMSA-2018-0011 published by VMware
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-25: exploited: Confirmed as exploited in the wild per CISA KEV entry