Lucene search

K

SD-WAN By VeloCloud Security Vulnerabilities

cve
cve

CVE-2020-3973

The VeloCloud Orchestrator does not apply correct input validation which allows for blind SQL-injection. A malicious actor with tenant access to Velocloud Orchestrator could enter specially crafted SQL queries and obtain data to which they are not...

8.8CVSS

8.8AI Score

0.001EPSS

2020-07-08 02:15 PM
25
cve
cve

CVE-2019-5533

In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Managed Service Provider accounts. Among the information is username, first and last name, phone numbers and e-mail...

4.3CVSS

4.3AI Score

0.001EPSS

2019-10-29 07:15 PM
42
cve
cve

CVE-2018-6961

VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware will be removing this service from the product in future...

8.1CVSS

8.2AI Score

0.298EPSS

2018-06-11 10:29 PM
837
In Wild