EXPOSURES › CVE-2018-6961
CVE-2018-6961
HIGH ⌖ ON CISA KEV · EXPLOITEDVMware SD-WAN Edge suffered a command injection flaw in its local web UI allowing remote code execution.
The local web UI component of VMware SD-WAN Edge by VeloCloud contained a command injection vulnerability that enabled remote code execution. DIB organizations must ensure such network edge devices are patched promptly, as unpatched RCE flaws in critical infrastructure can lead to supply-chain compromise or lateral movement. This failure is not a zero-day but was actively exploited in the wild, warranting a high embarrassment score due to the severity of RCE in a widely deployed product.
Shame score — A command injection vulnerability enabling remote code execution in a widely deployed SD-WAN edge device represents a severe, avoidable failure that attackers actively exploited in the wild.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.
| PRODUCT | STATUS |
|---|---|
| VMware Government Services (VGS) VMware, Inc. |
Authorized |
| Workspace ONE VMware, Inc. |
Authorized |