Skip to content
COOEY

EXPOSURES › CVE-2018-6961

CVE-2018-6961

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-6961 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

VMware SD-WAN Edge suffered a command injection flaw in its local web UI allowing remote code execution.

The local web UI component of VMware SD-WAN Edge by VeloCloud contained a command injection vulnerability that enabled remote code execution. DIB organizations must ensure such network edge devices are patched promptly, as unpatched RCE flaws in critical infrastructure can lead to supply-chain compromise or lateral movement. This failure is not a zero-day but was actively exploited in the wild, warranting a high embarrassment score due to the severity of RCE in a widely deployed product.

Shame score — A command injection vulnerability enabling remote code execution in a widely deployed SD-WAN edge device represents a severe, avoidable failure that attackers actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
VMware Government Services (VGS)
VMware, Inc.
Authorized
Workspace ONE
VMware, Inc.
Authorized