CVE-2024-22246: Command Injection
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution.
A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-22246?
CVE-2024-22246 has a high severity level due to the potential for remote code execution.
How do I fix CVE-2024-22246?
To mitigate CVE-2024-22246, apply the latest security patch provided by VMware for the SD-WAN Edge product.
Who is affected by CVE-2024-22246?
Users of VMware SD-WAN Edge are affected by CVE-2024-22246, particularly those with local access to the Edge Router UI.
What type of vulnerability is CVE-2024-22246?
CVE-2024-22246 is classified as an unauthenticated command injection vulnerability.
What could be the impact of exploiting CVE-2024-22246?
Exploitation of CVE-2024-22246 could lead to full control over the affected router.