CVE-2024-38817

MEDIUM

VMware NSX and Cloud Foundation - Authenticated Command Injection via NSX Edge CLI

Title source: llm
STIX 2.1

Description

VMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malicious payloads to execute arbitrary commands on the operating system as root.

Scores

CVSS v3 6.7
EPSS 0.0052
EPSS Percentile 39.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
n/a/VMware NSX, VMware Cloud Foundation VMware NSX 4.1.x, NSX-T 3.2.x
Published Oct 09, 2024
Tracked Since Feb 18, 2026