VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability
VMware · SD-WAN Edge
Date added (CISA)
2022-03-25
Remediation due
2022-04-15
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
VMware SD-WAN Edge by VeloCloud contains a command injection vulnerability in the local web UI component. Successful exploitation of this issue could result in remote code execution.