VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Feb 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Mon, 27 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_0
|
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published: 2018-06-11T22:00:00.000Z
Updated: 2025-10-21T23:45:50.384Z
Reserved: 2018-02-14T00:00:00.000Z
Link: CVE-2018-6961
Updated: 2024-08-05T06:17:17.275Z
Status : Modified
Published: 2018-06-11T22:29:00.230
Modified: 2025-10-22T00:16:25.823
Link: CVE-2018-6961
No data.