ZeroHour

CVE-2018-6961

KEV PoC moderate

Unauthenticated Command Injection in VMware SD-WAN Edge (VeloCloud) Web UI

CISA: VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability

CVSS 3.1
8.1 high
EPSS
86%p100
Published
()
KEV added
AI analysis

CVE-2018-6961 is a command injection vulnerability (CWE-78) in the local web UI component of VMware NSX SD-WAN Edge by VeloCloud, exploitable by an unauthenticated network attacker. The local web UI is disabled by default, so the flaw is only triggerable on deployments where that component has been enabled — VMware explicitly warned it should not be enabled on untrusted networks — and the high attack complexity in the CVSS vector reflects the need for such non-default conditions. Successful exploitation yields remote code execution on the edge appliance, with high impact on confidentiality, integrity, and availability. All VMware NSX SD-WAN Edge appliances running versions prior to 3.1.0 are affected, though practical exposure is limited to sites that enabled the local web UI. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25 (evidence of in-the-wild exploitation), and a public proof-of-concept exploit is available.

What to do: Upgrade VMware SD-WAN Edge firmware to version 3.1.0 or later per VMware's instructions, as required by the CISA KEV listing. Until patched, keep the local web UI disabled, or if it must be enabled, restrict it to trusted management networks only; audit appliances to confirm whether the local web UI is enabled and reachable. Note that VMware stated it would remove this component in later releases, so disabling it now is a safe interim measure.

Affected
VMware NSX SD-WAN Edge by VeloCloudprior to 3.1.0
Estimated exposure
moderateunknown precisely; plausibly on the order of a few thousand exposed edge appliances — No install counts or internet-exposure scan data are provided in the source data, so this is estimated from SD-WAN deployment patterns (edge appliances across many enterprise branch sites) discounted sharply because the vulnerable local…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.

CISA Known Exploited Vulnerability
Affected
VMware SD-WAN Edge
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
vmware
Products
nsx sd-wan by velocloud
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.