CVE-2023-37426
22.08.2023, 19:16
EdgeConnect SD-WAN Orchestrator instances prior to theversions resolved in this advisory were found to haveshared static SSH host keys for all installations. Thisvulnerability could allow an attacker to spoof the SSH hostsignature and thereby masquerade as a legitimate Orchestrator host.Enginsight
Vendor | Product | Version |
---|---|---|
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.0.0 ≤ 𝑥 ≤ 9.0.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.1.0 ≤ 𝑥 ≤ 9.1.7 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.2.0 ≤ 𝑥 ≤ 9.2.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.3.0 |
𝑥
= Vulnerable software versions