VMware Releases Security Updates for SD-WAN Edge and SD-WAN Orchestrator
The vulnerabilities could allow an attacker to remotely execute code, access the BIOS configuration or redirect a victim to an attacker-controlled domain
Summary
The vulnerabilities could allow an attacker to remotely execute code, access the BIOS configuration or redirect a victim to an attacker-controlled domain
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
VMware has released security updates to address multiple vulnerabilities in SD-WAN Edge and SD-WAN Orchestrator modules of the SD-WAN, which is a management software for wide area network deployments.
Vulnerability details
- CVE-2024-22246 - an unauthenticated command injection vulnerability in SD-WAN Edge with a CVSSv3 score of 7.4, which if exploited could allow an attacker to achieve remote code execution on the host machine.
- CVE-2024-22247 - a missing authentication and protection mechanism vulnerability in SD-WAN Edge. A malicious attacker with physical access to the SD-WAN Edge appliance during activation could exploit this vulnerability to access the BIOS configuration or exploit the default boot priority.
- CVE-2024-22248 - an open redirect vulnerability in SD-WAN Orchestrator. A malicious attacker may be able to redirect a victim to an attacker controlled domain due to improper path handling, leading to sensitive information disclosure.
Remediation advice
Affected organisations are encouraged to review VMware Security Advisory VMSA-2024-0008 and apply any relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 18 April 2024 4:25 pm