First published: Thu Nov 03 2022(Updated: )
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Sd-wan | >=8.7.0.0-2.3.0.0<8.7.0.0-2.3.0.6 | |
Arubanetworks Arubaos | >=6.5.4.0<6.5.4.22 | |
Arubanetworks Arubaos | >=8.4.0.0<8.6.0.17 | |
Arubanetworks Arubaos | >=8.7.0.0<8.7.1.9 | |
Arubanetworks Arubaos | >=8.8.0.0<=8.9.03 | |
Arubanetworks Arubaos | =10.3.0.0 | |
Arubanetworks 7005 | ||
Arubanetworks 7008 | ||
Arubanetworks 7010 | ||
Arubanetworks 7024 | ||
Arubanetworks 7030 | ||
Arubanetworks 7205 | ||
Arubanetworks 7210 | ||
Arubanetworks 7220 | ||
Arubanetworks 7240xm | ||
Arubanetworks 7280 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the ArubaOS vulnerability is CVE-2022-37904.
The affected software versions for this vulnerability are Arubanetworks Sd-wan version 8.7.0.0-2.3.0.0 through 8.7.0.0-2.3.0.6, Arubanetworks Arubaos version 6.5.4.0 through 6.5.4.22, Arubanetworks Arubaos version 8.4.0.0 through 8.6.0.17, Arubanetworks Arubaos version 8.7.0.0 through 8.7.1.9, Arubanetworks Arubaos version 8.8.0.0 through 8.9.03, and Arubanetworks Arubaos version 10.3.0.0.
The severity rating of CVE-2022-37904 vulnerability is high with a value of 8.8.
An attacker can exploit the vulnerability by executing arbitrary code during the boot sequence.
Successful exploitation of this vulnerability can result in permanent modification of the underlying operating system.