First published: Tue Apr 02 2024(Updated: )
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command injection attack that could lead to full control of the router.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
VMware SD-WAN Edge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-22246 has a high severity level due to the potential for remote code execution.
To mitigate CVE-2024-22246, apply the latest security patch provided by VMware for the SD-WAN Edge product.
Users of VMware SD-WAN Edge are affected by CVE-2024-22246, particularly those with local access to the Edge Router UI.
CVE-2024-22246 is classified as an unauthenticated command injection vulnerability.
Exploitation of CVE-2024-22246 could lead to full control over the affected router.