« Volver al listado

CVE-2024-22247

Estado: AplazadaMedia (4.8)—

VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability.

A malicious actor with physical access to the SD-WAN Edge appliance during activation can potentially exploit this vulnerability to access the BIOS configuration. In addition, the malicious actor may be able to exploit the default boot priority configured.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-22247",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-22247",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-02T18:00:39.986241Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "N/A",
          "product": "VMware SD-WAN Edge",
          "versions": [
            {
              "status": "affected",
              "version": "VMware SD-WAN Edge 4.5.x, VMware SD-WAN Edge 5.x"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:vmware:sd-wan_edge:4.5.x:*:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "sd-wan_edge",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.x"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:vmware:sd-wan_edge:5.x:*:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "sd-wan_edge",
          "versions": [
            {
              "status": "affected",
              "version": "5.x"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-04-02T16:15:07.833",
  "references": [
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2024-0008.html",
      "source": "security@vmware.com"
    },
    {
      "url": "https://www.vmware.com/security/advisories/VMSA-2024-0008.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "VMware SD-WAN Edge contains a missing authentication and protection mechanism vulnerability.\n\nA malicious actor with physical access to the SD-WAN Edge appliance \nduring activation can potentially exploit this vulnerability to access \nthe BIOS configuration. In addition, the malicious actor may be able to \nexploit the default boot priority configured.\n\n"
    },
    {
      "lang": "es",
      "value": "VMware SD-WAN Edge contiene una vulnerabilidad de mecanismo de autenticación y protección faltante. Un actor malintencionado con acceso físico al dispositivo SD-WAN Edge durante la activación puede explotar esta vulnerabilidad para acceder a la configuración del BIOS. Además, el actor malintencionado puede aprovechar la prioridad de arranque predeterminada configurada."
    }
  ],
  "lastModified": "2026-06-17T07:11:01.577",
  "sourceIdentifier": "security@vmware.com"
}