VMware SD-WAN Edge是美国威睿(VMware)公司的一套网络和安全虚拟化平台。该平台为虚拟机提供部署在普通IP网络硬件上、可编程以及可移动的虚拟网络。 VMware NSX SD-WAN Edge by VeloCloud 3.1.0之前版本中的local Web UI组件存在命令注入漏洞。远程攻击者利用该漏洞在受影响应用程序的上下文中执行任意代码或造成拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| VMware | NSX SD-WAN by VeloCloud | prior to version 3.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | veloCloud VMWare - Vulnerability | https://github.com/bokanrb/CVE-2018-6961 | POC Details |
| 2 | VMware NSX SD-WAN command injection vulnerability | https://github.com/r3dxpl0it/CVE-2018-6961 | POC Details |
| 3 | VMware NSX SD-WAN Edge (formerly VeloCloud Edge) before 3.1.2 contains an unauthenticated command injection in the local web UI diagnostic tools (Ping/Traceroute). This template detects it reliably by injecting 'id', 'whoami', and a random marker. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2018/CVE-2018-6961.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet