First published: Thu Nov 03 2022(Updated: )
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba Networks SD-WAN | >=8.7.0.0-2.3.0.0<8.7.0.0-2.3.0.6 | |
ArubaOS | >=6.5.4.0<6.5.4.22 | |
ArubaOS | >=8.4.0.0<8.6.0.17 | |
ArubaOS | >=8.7.0.0<8.7.1.9 | |
ArubaOS | >=8.8.0.0<10.3.0.1 | |
Aruba Networks 7005 | ||
Aruba Networks 7008 | ||
Aruba 7010 | ||
Aruba Networks 7024 | ||
Aruba Networks 7030 | ||
Aruba Networks 7205 | ||
Aruba Networks 7210 | ||
Aruba Networks 7220 | ||
Aruba Networks 7240XM | ||
Aruba Networks 7280 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37908 is a vulnerability that allows an authenticated attacker to impact the integrity of the ArubaOS bootloader on 7xxx series controllers, compromising the hardware chain of trust.
CVE-2022-37908 affects the ArubaOS bootloader on 7xxx series controllers, potentially compromising the entire hardware chain of trust.
ArubaOS versions 6.5.4.0 to 6.5.4.22, 8.4.0.0 to 8.6.0.17, and 8.7.0.0 to 8.7.1.9 are affected by CVE-2022-37908.
CVE-2022-37908 has a severity level of 6.5 out of 10, which is considered medium.
Aruba Networks has released a security advisory with mitigation steps, which can be found at the referenced link.