First published: Thu Nov 03 2022(Updated: )
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Sd-wan | >=8.7.0.0-2.3.0.0<8.7.0.0-2.3.0.6 | |
Arubanetworks Arubaos | >=6.5.4.0<6.5.4.22 | |
Arubanetworks Arubaos | >=8.4.0.0<8.6.0.17 | |
Arubanetworks Arubaos | >=8.7.0.0<8.7.1.9 | |
Arubanetworks Arubaos | >=8.8.0.0<10.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37906 is an authenticated path traversal vulnerability in the ArubaOS command line interface that allows an attacker to delete arbitrary files.
CVE-2022-37906 has a severity rating of 8.1, which is considered high.
CVE-2022-37906 affects the following software versions: - Arubanetworks Sd-wan (8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.6) - Arubanetworks Arubaos (6.5.4.0 to 6.5.4.22) - Arubanetworks Arubaos (8.4.0.0 to 8.6.0.17) - Arubanetworks Arubaos (8.7.0.0 to 8.7.1.9) - Arubanetworks Arubaos (8.8.0.0 to 10.3.0.1)
You need to have authentication credentials and be able to run commands in the ArubaOS command line interface to exploit CVE-2022-37906.
To fix CVE-2022-37906, it is recommended to update to the latest version of the affected software provided by ArubaNetworks.