CVE-2022-37905: High severity aruba networks sd-wan vulnerability
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37905?
CVE-2022-37905 is a vulnerability in ArubaOS running on 7xxx series controllers that allows an attacker to execute arbitrary code during the boot sequence.
What is the severity of CVE-2022-37905?
The severity of CVE-2022-37905 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2022-37905?
ArubaOS versions 6.5.4.0 to 6.5.4.22, 8.4.0.0 to 8.6.0.17, 8.7.0.0 to 8.7.1.9, 8.8.0.0 to 8.9.0.3, and 10.3.0.0 are affected by CVE-2022-37905.
How can an attacker exploit CVE-2022-37905?
An attacker can exploit CVE-2022-37905 by leveraging the vulnerability to execute arbitrary code during the boot sequence of ArubaOS on 7xxx series controllers.
Is there a fix available for CVE-2022-37905?
Yes, Aruba Networks has provided a fix for CVE-2022-37905. It is recommended to update to the latest version of ArubaOS to mitigate this vulnerability.