First published: Thu Nov 03 2022(Updated: )
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba Networks SD-WAN | >=8.7.0.0-2.3.0.0<8.7.0.0-2.3.0.6 | |
arubanetworks ArubaOS | >=6.5.4.0<6.5.4.22 | |
arubanetworks ArubaOS | >=8.4.0.0<8.6.0.17 | |
arubanetworks ArubaOS | >=8.7.0.0<8.7.1.9 | |
arubanetworks ArubaOS | >=8.8.0.0<=8.9.03 | |
arubanetworks ArubaOS | =10.3.0.0 | |
Aruba Networks 7005 | ||
Aruba Networks 7008 | ||
Aruba 7010 | ||
Aruba Networks 7024 | ||
Aruba Networks 7030 | ||
Aruba Networks 7205 | ||
Aruba Networks 7210 | ||
Aruba Networks 7220 | ||
Aruba Networks 7240XM | ||
Aruba Networks 7280 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the ArubaOS vulnerability is CVE-2022-37904.
The affected software versions for this vulnerability are Arubanetworks Sd-wan version 8.7.0.0-2.3.0.0 through 8.7.0.0-2.3.0.6, Arubanetworks Arubaos version 6.5.4.0 through 6.5.4.22, Arubanetworks Arubaos version 8.4.0.0 through 8.6.0.17, Arubanetworks Arubaos version 8.7.0.0 through 8.7.1.9, Arubanetworks Arubaos version 8.8.0.0 through 8.9.03, and Arubanetworks Arubaos version 10.3.0.0.
The severity rating of CVE-2022-37904 vulnerability is high with a value of 8.8.
An attacker can exploit the vulnerability by executing arbitrary code during the boot sequence.
Successful exploitation of this vulnerability can result in permanent modification of the underlying operating system.