CVE-2024-22247

MEDIUM

VMware SD-WAN Edge - Privilege Escalation

Title source: llm
STIX 2.1

Description

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

References (1)

Core 1

Scores

CVSS v3 4.8
EPSS 0.0022
EPSS Percentile 11.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-287
Status published
Products (1)
N/A/VMware SD-WAN Edge VMware SD-WAN Edge 4.5.x, VMware SD-WAN Edge 5.x
Published Apr 02, 2024
Tracked Since Feb 18, 2026