First published: Thu Nov 03 2022(Updated: )
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Sd-wan | >=8.7.0.0-2.3.0.0<8.7.0.0-2.3.0.6 | |
Arubanetworks Arubaos | >=6.5.4.0<6.5.4.22 | |
Arubanetworks Arubaos | >=8.4.0.0<8.6.0.17 | |
Arubanetworks Arubaos | >=8.7.0.0<8.7.1.9 | |
Arubanetworks Arubaos | >=8.8.0.0<10.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37911 is a vulnerability in the command line interface of ArubaOS that allows an authenticated attacker to retrieve files from the local system or cause a denial of service.
CVE-2022-37911 affects ArubaOS by potentially allowing an authenticated attacker to retrieve files or cause a denial of service.
ArubaOS versions between 6.5.4.0 and 6.5.4.22, 8.4.0.0 and 8.6.0.17, 8.7.0.0 and 8.7.1.9, and 8.8.0.0 and 10.3.0.1 are affected by CVE-2022-37911.
CVE-2022-37911 has a severity rating of 5.5 (medium).
Aruba Networks has released a patch to address the vulnerabilities in ArubaOS. It is recommended to apply the necessary updates to mitigate the risks of CVE-2022-37911.