CVE-2017-4929Cross-site Scripting in Vmware NSX Edge

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 55.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 17
Latest updateMay 17

Description

VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages5 packages

CVEListV5vmware/nsx_edge6.2.x before 6.2.9, 6.3.x before 6.3.5+1
NVDvmware/nsx_edge14 versions+13

Patches

🔴Vulnerability Details

1
GHSA
GHSA-qvjc-9gm9-g5qq: VMware NSX Edge (62022-05-17

📋Vendor Advisories

2
VMware
NSX for vSphere update addresses NSX Edge Cross-Site Scripting (XSS) issue.2017-11-16
VMware
VMware vCenter Server update resolves LDAP DoS, SSRF and CRLF injection issues2017-11-09