A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
Subscriptions
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-37639 | VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 10 Oct 2024 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root. | VMware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root. |
Wed, 09 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware cloud Foundation Vmware nsx Vmware nsx-t |
|
| CPEs | cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:nsx-t:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:nsx:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Vmware
Vmware cloud Foundation Vmware nsx Vmware nsx-t |
|
| Metrics |
ssvc
|
Wed, 09 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mware NSX contains a command injection vulnerability. A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root. | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2024-10-10T07:54:34.429Z
Reserved: 2024-06-19T22:32:06.582Z
Link: CVE-2024-38817
Updated: 2024-10-09T20:28:10.427Z
Status : Awaiting Analysis
Published: 2024-10-09T20:15:08.037
Modified: 2024-10-10T12:51:56.987
Link: CVE-2024-38817
No data.
OpenCVE Enrichment
No data.
EUVD