peter bassill · operator
$ cve CVE-2018-6961 JSON

CVE-2018-6961 KEV EXPLOIT

8.1
HIGH · CVSS 3.1 · EPSS 86.3% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.

Scoring

CVSS8.1 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS86.25% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2018-06-11
Last modified2026-06-17

CISA KEV

NameVMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productVMware / SD-WAN Edge
Ransomware usenone reported

Affected (1)

VendorProduct
vmwarensx sd-wan by velocloud

Public exploits

SourceTitleDate
exploit-dbVMware NSX SD-WAN Edge < 3.1.2 - Command Injection2018-07-02

References

→ the Explorer  ·  watch your stack  ·  NVD