Vulnerability record · CVE-2018-6961 · published 11 June 2018
CVE-2018-6961: VMware NSX SD-WAN Edge local web UI command injection
Vmware · Nsx Sd Wan By Velocloud
VMware NSX SD-WAN Edge by VeloCloud before version 3.1.0 contains an OS command injection flaw (CWE-78) in its local web UI component. The component is disabled by default and VMware advises against enabling it on untrusted networks, but when reachable it allows remote code execution. It matters because the flaw is confirmed exploited in the wild and carries a very high EPSS probability.
Description
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future releases. Successful exploitation of this issue could result in remote code execution.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityConfirmed exploitation (CISA KEV) combined with a very high EPSS score and remote code execution impact warrants urgent remediation despite the service being disabled by default.
What it is
VMware NSX SD-WAN Edge by VeloCloud before version 3.1.0 contains an OS command injection flaw (CWE-78) in its local web UI component. The component is disabled by default and VMware advises against enabling it on untrusted networks, but when reachable it allows remote code execution. It matters because the flaw is confirmed exploited in the wild and carries a very high EPSS probability.
Impact
A successful attacker executes arbitrary commands on the edge device, gaining code execution with the privileges of the web UI service. That can lead to full compromise of the appliance and any trust it holds in the SD-WAN fabric.
Attack surface
Reachable over the network via the local web UI (CVSS vector AV:N, PR:N, UI:N), so no authentication or user interaction is required. The service is disabled by default, so exposure depends on an administrator having enabled it, and it should not be exposed to untrusted networks.
Exploitation
CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25 with a 2022-04-15 remediation due date, and a public Exploit-DB entry (44959) exists. EPSS gives a 30-day probability of 0.86252 (99.7th percentile), indicating high likelihood of exploitation activity.
What to do
- Upgrade NSX SD-WAN Edge by VeloCloud to version 3.1.0 or later per the vendor advisory VMSA-2018-0011.
- Keep the local web UI component disabled unless operationally required, and never expose it to untrusted networks.
- Restrict management access to the web UI with firewall rules and network segmentation to trusted admin networks only.
- Monitor for the service being re-enabled and treat any exposure as urgent given active exploitation.
- Plan for the vendor's removal of this service in future releases and migrate off it.
Detection
- Audit edge devices for the local web UI service being enabled and reachable from untrusted networks.
- Inspect web server and system logs for command injection patterns or unexpected shell metacharacters in web UI requests.
- Monitor for unexpected child processes or shell execution spawned by the web UI service on edge appliances.
- Alert on outbound connections from edge devices to unknown hosts that could indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-6961 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/104185 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041210 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.vmware.com/security/advisories/VMSA-2018-0011.html | Vendor Advisory |
| https://www.exploit-db.com/exploits/44959/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/104185 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1041210 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.vmware.com/security/advisories/VMSA-2018-0011.html | Vendor Advisory |
| https://www.exploit-db.com/exploits/44959/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-6961 | US Government Resource |
Track CVE-2018-6961 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-6961), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.