VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|
Mon, 27 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_0
|
cvssV3_1
|

Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-02-07T16:38:21.489Z
Reserved: 2018-02-14T00:00:00.000Z
Link: CVE-2018-6961

Updated: 2024-08-05T06:17:17.275Z

Status : Analyzed
Published: 2018-06-11T22:29:00.230
Modified: 2025-02-12T20:05:57.833
Link: CVE-2018-6961

No data.