First published: Fri Oct 07 2022(Updated: )
Unauthenticated buffer overflow vulnerabilities exist within the Aruba InstantOS and ArubaOS 10 web management interface. Successful exploitation results in the execution of arbitrary commands on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InnstantOS that address these security vulnerabilities.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Arubaos | >=10.3.0.0<10.3.1.1 | |
Arubanetworks Instant | >=6.4.0.0<6.4.4.8-4.2.4.21 | |
Arubanetworks Instant | >=6.5.0.0<6.5.4.24 | |
Arubanetworks Instant | >=8.6.0.0<8.6.0.19 | |
Arubanetworks Instant | >=8.7.0.0<8.7.1.10 | |
Arubanetworks Instant | >=8.10.0.0<8.10.0.2 | |
Siemens Scalance W1750d Firmware | ||
Siemens SCALANCE W1750D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37890 is an unauthenticated buffer overflow vulnerability in the Aruba InstantOS and ArubaOS 10 web management interface.
CVE-2022-37890 has a severity rating of 9.8 out of 10, indicating a critical vulnerability.
CVE-2022-37890 affects Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.0.0-6.5.4.24; Aruba InstantOS 8.6.x: 8.6.0.0-8.6.0.19; Aruba InstantOS 8.7.x: 8.7.0.0-8.7.1.10; and Aruba InstantOS 8.10.x: 8.10.0.0-8.10.0.2.
CVE-2022-37890 can be exploited by an attacker to execute arbitrary commands on the underlying operating system of the affected Aruba InstantOS and ArubaOS 10 devices.
Siemens Scalance W1750d devices are not vulnerable to CVE-2022-37890.