CVE-2023-37424
22.08.2023, 19:16
A vulnerability in the web-based management interfaceof EdgeConnect SD-WAN Orchestrator could allow anunauthenticated remote attacker to run arbitrary commands onthe underlying host if certain preconditions outside of theattacker's control are met. Successful exploitation of thisvulnerability could allow an attacker to execute arbitrarycommands on the underlying operating system leading tocomplete system compromise.
Vendor | Product | Version |
---|---|---|
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.0.0 ≤ 𝑥 ≤ 9.0.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.1.0 ≤ 𝑥 ≤ 9.1.7 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.2.0 ≤ 𝑥 ≤ 9.2.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.3.0 |
𝑥
= Vulnerable software versions