CVE-2022-43518

An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
hpeCNA
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
VendorProductVersion
arubanetworksedgeconnect_enterprise
8.3.1.0 ≤
𝑥
≤ 8.3.7.1
arubanetworksedgeconnect_enterprise
9.0.0.0 ≤
𝑥
≤ 9.0.7.0
arubanetworksedgeconnect_enterprise
9.1.0.0 ≤
𝑥
≤ 9.1.3.0
arubanetworksedgeconnect_enterprise
9.2.0.0 ≤
𝑥
≤ 9.2.1.0
𝑥
= Vulnerable software versions