CVE-2023-37427
22.08.2023, 19:16
A vulnerability in the web-based management interface ofEdgeConnect SD-WAN Orchestrator could allow an authenticatedremote attacker to run arbitrary commands on the underlyinghost. Successful exploitation of this vulnerability allowsan attacker to execute arbitrary commands as root on theunderlying operating system leading to complete systemcompromise.
Vendor | Product | Version |
---|---|---|
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.0.0 ≤ 𝑥 ≤ 9.0.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.1.0 ≤ 𝑥 ≤ 9.1.7 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.2.0 ≤ 𝑥 ≤ 9.2.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.3.0 |
𝑥
= Vulnerable software versions