CVE-2023-37425
22.08.2023, 19:16
A vulnerability in the web-based management interfaceof EdgeConnect SD-WAN Orchestrator could allow anunauthenticated remote attacker to conduct a storedcross-site scripting (XSS) attack against an administrativeuser of the interface. A successful exploit allows anattacker to execute arbitrary script code in a victim'sbrowser in the context of the affected interface.
Vendor | Product | Version |
---|---|---|
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.0.0 ≤ 𝑥 ≤ 9.0.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.1.0 ≤ 𝑥 ≤ 9.1.7 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.2.0 ≤ 𝑥 ≤ 9.2.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.3.0 |
𝑥
= Vulnerable software versions