CyberSec.Space Logo
Back to CVE Browser

CVE-2018-6961

Known Exploited (CISA KEV)HIGH
8.1
CVSS Severity Score
EPSS Score57.1240%
EPSS Percentile86.75th
PublishedJun 11, 2018
Last ModifiedOct 30, 2025

Vulnerability Description

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.

Affected Platforms (CPE)

πŸ“¦
Vmware

Nsx Sd Wan By Velocloud

< 3.1.0

References & Advisories

Related Vulnerabilities