CVE-2022-37903: High severity aruba networks sd-wan vulnerability
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37903?
CVE-2022-37903 is a vulnerability that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface.
What is the severity of CVE-2022-37903?
CVE-2022-37903 has a severity rating of 8.8, which is considered high.
Which software is affected by CVE-2022-37903?
The following software versions are affected: Arubanetworks SD-WAN 8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.7, Arubanetworks ArubaOS 6.5.4.0 to 6.5.4.23, Arubanetworks ArubaOS 8.4.0.0 to 8.6.0.18, Arubanetworks ArubaOS 8.7.0.0 to 8.7.1.10, Arubanetworks ArubaOS 8.8.0.0 to 8.9.0.3, and Arubanetworks ArubaOS 10.3.0.0.
How can CVE-2022-37903 be exploited?
CVE-2022-37903 can be exploited by an authenticated attacker through the web interface to overwrite a file with attacker-controlled content.
How can I fix CVE-2022-37903?
To fix CVE-2022-37903, it is recommended to apply the necessary patches or updates provided by Arubanetworks. Refer to their official advisory for more information.