CVE-2023-37428
22.08.2023, 19:16
A vulnerability in the EdgeConnect SD-WAN Orchestratorweb-based management interface allows remote authenticatedusers to run arbitrary commands on the underlying host.A successful exploit could allow an attacker to executearbitrary commands as root on the underlying operating systemleading to complete system compromise.
Vendor | Product | Version |
---|---|---|
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.0.0 ≤ 𝑥 ≤ 9.0.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.1.0 ≤ 𝑥 ≤ 9.1.7 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.2.0 ≤ 𝑥 ≤ 9.2.5 |
arubanetworks | edgeconnect_sd-wan_orchestrator | 9.3.0 |
𝑥
= Vulnerable software versions