CVE-2022-37890: Buffer Overflow
Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37890?
CVE-2022-37890 is an unauthenticated buffer overflow vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface.
What is the severity of CVE-2022-37890?
CVE-2022-37890 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
Which software is affected by CVE-2022-37890?
CVE-2022-37890 affects Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.0.0-6.5.4.24; Aruba InstantOS 8.6.x: 8.6.0.0-8.6.0.19; Aruba InstantOS 8.7.x: 8.7.0.0-8.7.1.10; and Aruba InstantOS 8.10.x: 8.10.0.0-8.10.0.2.
How can CVE-2022-37890 be exploited?
CVE-2022-37890 can be exploited by an attacker to execute arbitrary commands on the underlying operating system of the affected Aruba InstantOS and ArubaOS 10 devices.
Are Siemens Scalance W1750d devices vulnerable to CVE-2022-37890?
Siemens Scalance W1750d devices are not vulnerable to CVE-2022-37890.