CVE-2023-37440
22.08.2023, 19:16
A vulnerability in the web-based management interfaceof EdgeConnect SD-WAN Orchestrator could allow anunauthenticated remote attacker to conduct a server-siderequest forgery (SSRF) attack. A successful exploit allowsan attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leadingto potential disclosure of sensitive information.
Vendor | Product | Version |
---|---|---|
arubanetworks | edgeconnect_sd-wan_orchestrator | 𝑥 < 9.3.1 |
𝑥
= Vulnerable software versions