CVE-2022-37906: Path Traversal
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37906?
CVE-2022-37906 is an authenticated path traversal vulnerability in the ArubaOS command line interface that allows an attacker to delete arbitrary files.
What is the severity of CVE-2022-37906?
CVE-2022-37906 has a severity rating of 8.1, which is considered high.
Which software versions are affected by CVE-2022-37906?
CVE-2022-37906 affects the following software versions: - Arubanetworks Sd-wan (8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.6) - Arubanetworks Arubaos (6.5.4.0 to 6.5.4.22) - Arubanetworks Arubaos (8.4.0.0 to 8.6.0.17) - Arubanetworks Arubaos (8.7.0.0 to 8.7.1.9) - Arubanetworks Arubaos (8.8.0.0 to 10.3.0.1)
How can I exploit CVE-2022-37906?
You need to have authentication credentials and be able to run commands in the ArubaOS command line interface to exploit CVE-2022-37906.
How can I fix CVE-2022-37906?
To fix CVE-2022-37906, it is recommended to update to the latest version of the affected software provided by ArubaNetworks.