VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: vmware
Published: 2018-06-11T22:00:00Z
Updated: 2024-09-17T01:36:00.106Z
Reserved: 2018-02-14T00:00:00
Link: CVE-2018-6961
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-11T22:29:00.230
Modified: 2024-11-21T04:11:29.293
Link: CVE-2018-6961
Redhat
No data.