CVE-2018-6961
גבוהה 8.1 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
מדדים
- CVSS 3.1
-
8.1 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 86% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-78
מוצרים מושפעים
vmware: nsx sd-wan by velocloud
קישורים
- http://www.vmware.com/security/advisories/VMSA-2018-0011.html Vendor Advisory
- http://www.vmware.com/security/advisories/VMSA-2018-0011.html Vendor Advisory
- https://www.exploit-db.com/exploits/44959/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44959/ ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/104185 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041210 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/104185 Broken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041210 Broken LinkThird Party AdvisoryVDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource