First published: Thu Nov 03 2022(Updated: )
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Sd-wan | >=8.7.0.0-2.3.0.0<8.7.0.0-2.3.0.6 | |
Arubanetworks Arubaos | >=6.5.4.0<6.5.4.22 | |
Arubanetworks Arubaos | >=8.4.0.0<8.6.0.17 | |
Arubanetworks Arubaos | >=8.7.0.0<8.7.1.9 | |
Arubanetworks Arubaos | >=8.8.0.0<10.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37909 is a vulnerability in certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs.
CVE-2022-37909 has a severity rating of 5.3 (medium).
Versions 8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.6 of Arubanetworks Sd-wan, versions 6.5.4.0 to 6.5.4.22 of Arubanetworks Arubaos, versions 8.4.0.0 to 8.6.0.17 of Arubanetworks Arubaos, versions 8.7.0.0 to 8.7.1.9 of Arubanetworks Arubaos, and versions 8.8.0.0 to 10.3.0.1 of Arubanetworks Arubaos are affected by CVE-2022-37909.
The disclosure of potentially sensitive information can occur in complex scenarios and depends on factors beyond the control of attackers.
Aruba has released a security advisory that provides guidance on mitigating the vulnerability. Please refer to the official Aruba security advisory for specific instructions.