Cyber Security News

VMware NSX Vulnerabilities Allow Hackers To Execute Arbitrary Commands

VMware has issued a critical advisory (VMSA-2024-0020) detailing multiple vulnerabilities in its NSX and Cloud Foundation products.

These vulnerabilities, identified as CVE-2024-38818, CVE-2024-38817, and CVE-2024-38815, could potentially allow malicious actors to execute arbitrary commands, escalate privileges, and conduct content spoofing attacks.

  • VMware NSX
  • VMware Cloud Foundation

Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try for Free

Vulnerability Details

1. Command Injection Vulnerability (CVE-2024-38817)

VMware NSX contains a command injection vulnerability that allows a malicious actor with access to the NSX Edge CLI terminal to execute arbitrary commands on the operating system as root.

This vulnerability has been rated as Moderate with a CVSSv3 base score of 6.7.

2. Local Privilege Escalation Vulnerability (CVE-2024-38818)

VMware NSX also contains a local privilege escalation vulnerability, which could allow an authenticated malicious actor to obtain permissions from a group role that is separate from what was previously assigned.

This vulnerability has also been rated as Moderate with a CVSSv3 base score of 6.7.

3. Content Spoofing Vulnerability (CVE-2024-38815)

Furthermore, VMware NSX contains a content spoofing vulnerability that could allow an unauthenticated malicious actor to craft a URL and redirect a victim to an attacker-controlled domain, leading to sensitive information disclosure.

This vulnerability has been rated as Moderate with a CVSSv3 base score of 4.327.

It is recommended that organizations check for the current version of VMware NSX installed in their environment. This can be done by logging into the NSX Manager web interface and checking the version information.

To remediate these vulnerabilities, users are advised to update to the versions listed in the ‘Fixed Version’ column of the ‘Response Matrix’ provided by VMware. No workarounds are available for these vulnerabilities.

VMware has thanked several researchers for responsibly reporting these issues, including n3k from TIANGONG Team of Legendsec at QI-ANXIN Group, Allan Pinto and Kumaran Ravichandran of Westpac Banking Corporation, Benjamin Johns of IQ Consult, and Aymane CHAKI of Excellium Cyber Solutions by Thales.

Strategies to Protect Websites & APIs from Malware Attack => Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago