Description
VMware NSX contains a command injection vulnerability. 

A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
Published: 2024-10-09
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-37639 VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
History

Thu, 10 Oct 2024 08:15:00 +0000

Type Values Removed Values Added
Description Mware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root. VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.

Wed, 09 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Vmware
Vmware cloud Foundation
Vmware nsx
Vmware nsx-t
CPEs cpe:2.3:a:vmware:cloud_foundation:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:nsx-t:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:nsx:*:*:*:*:*:*:*:*
Vendors & Products Vmware
Vmware cloud Foundation
Vmware nsx
Vmware nsx-t
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Description Mware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Vmware Cloud Foundation Nsx Nsx-t
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2024-10-10T07:54:34.429Z

Reserved: 2024-06-19T22:32:06.582Z

Link: CVE-2024-38817

cve-icon Vulnrichment

Updated: 2024-10-09T20:28:10.427Z

cve-icon NVD

Status : Deferred

Published: 2024-10-09T20:15:08.037

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-38817

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses