SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2024-22247

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability.

MEDIUM 4.8EPSS 0.21%

Does this matter?

Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.

Description

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability. A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS
0.21% probability · 12th percentile
CISA KEV
Not listed
Weakness
CWE-287
Source
security@vmware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.