CVE-2022-37904: High severity aruba networks sd-wan vulnerability
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the ArubaOS vulnerability?
The vulnerability ID for the ArubaOS vulnerability is CVE-2022-37904.
What are the affected software versions for this vulnerability?
The affected software versions for this vulnerability are Arubanetworks Sd-wan version 8.7.0.0-2.3.0.0 through 8.7.0.0-2.3.0.6, Arubanetworks Arubaos version 6.5.4.0 through 6.5.4.22, Arubanetworks Arubaos version 8.4.0.0 through 8.6.0.17, Arubanetworks Arubaos version 8.7.0.0 through 8.7.1.9, Arubanetworks Arubaos version 8.8.0.0 through 8.9.03, and Arubanetworks Arubaos version 10.3.0.0.
What is the severity rating of CVE-2022-37904 vulnerability?
The severity rating of CVE-2022-37904 vulnerability is high with a value of 8.8.
How can an attacker exploit the vulnerability?
An attacker can exploit the vulnerability by executing arbitrary code during the boot sequence.
What can be the impact of successful exploitation of this vulnerability?
Successful exploitation of this vulnerability can result in permanent modification of the underlying operating system.