CVE-2022-37911: XEE
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37911?
CVE-2022-37911 is a vulnerability in the command line interface of ArubaOS that allows an authenticated attacker to retrieve files from the local system or cause a denial of service.
How does CVE-2022-37911 impact ArubaOS?
CVE-2022-37911 affects ArubaOS by potentially allowing an authenticated attacker to retrieve files or cause a denial of service.
Which versions of ArubaOS are affected by CVE-2022-37911?
ArubaOS versions between 6.5.4.0 and 6.5.4.22, 8.4.0.0 and 8.6.0.17, 8.7.0.0 and 8.7.1.9, and 8.8.0.0 and 10.3.0.1 are affected by CVE-2022-37911.
What is the severity of CVE-2022-37911?
CVE-2022-37911 has a severity rating of 5.5 (medium).
Is there a fix available for CVE-2022-37911?
Aruba Networks has released a patch to address the vulnerabilities in ArubaOS. It is recommended to apply the necessary updates to mitigate the risks of CVE-2022-37911.