CVE-2022-37908: Medium severity aruba networks sd-wan vulnerability
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37908?
CVE-2022-37908 is a vulnerability that allows an authenticated attacker to impact the integrity of the ArubaOS bootloader on 7xxx series controllers, compromising the hardware chain of trust.
How does CVE-2022-37908 impact ArubaOS?
CVE-2022-37908 affects the ArubaOS bootloader on 7xxx series controllers, potentially compromising the entire hardware chain of trust.
Which software versions are affected by CVE-2022-37908?
ArubaOS versions 6.5.4.0 to 6.5.4.22, 8.4.0.0 to 8.6.0.17, and 8.7.0.0 to 8.7.1.9 are affected by CVE-2022-37908.
What is the severity of CVE-2022-37908?
CVE-2022-37908 has a severity level of 6.5 out of 10, which is considered medium.
Is there a fix for CVE-2022-37908?
Aruba Networks has released a security advisory with mitigation steps, which can be found at the referenced link.