CVE-2018-6961
KEV PoC moderateUnauthenticated Command Injection in VMware SD-WAN Edge (VeloCloud) Web UI
CISA: VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
CVE-2018-6961 is a command injection vulnerability (CWE-78) in the local web UI component of VMware NSX SD-WAN Edge by VeloCloud, exploitable by an unauthenticated network attacker. The local web UI is disabled by default, so the flaw is only triggerable on deployments where that component has been enabled — VMware explicitly warned it should not be enabled on untrusted networks — and the high attack complexity in the CVSS vector reflects the need for such non-default conditions. Successful exploitation yields remote code execution on the edge appliance, with high impact on confidentiality, integrity, and availability. All VMware NSX SD-WAN Edge appliances running versions prior to 3.1.0 are affected, though practical exposure is limited to sites that enabled the local web UI. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 (evidence of in-the-wild exploitation), and a public proof-of-concept exploit is available.
What to do: Upgrade VMware SD-WAN Edge firmware to version 3.1.0 or later per VMware's instructions, as required by the CISA KEV listing. Until patched, keep the local web UI disabled, or if it must be enabled, restrict it to trusted management networks only; audit appliances to confirm whether the local web UI is enabled and reachable. Note that VMware stated it would remove this component in later releases, so disabling it now is a safe interim measure.
| VMware NSX SD-WAN Edge by VeloCloud | prior to 3.1.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
- Affected
- VMware SD-WAN Edge
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- vmware
- Products
- nsx sd-wan by velocloud
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.