CVE-2018-6961 is a critical command injection vulnerability affecting VMware NSX SD-WAN Edge by VeloCloud versions prior to 3.1.0, specifically within its local web UI component. This flaw carries a CVSS score of 8.1 (High) due to its network-based attack vector, low attack complexity, and potential for unauthenticated remote code execution, leading to full compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited, listed in the CISA KEV catalog, and has publicly available exploit code, including a Nuclei template and an ExploitDB entry, garnering significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.0CPE matchmatch criteria | cpe:2.3:a:vmware:nsx_sd-wan_by_velocloud:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.