CVE-2022-37912: OS Command Injection
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-37912?
CVE-2022-37912 is an authenticated command injection vulnerability in the ArubaOS command line interface.
What is the severity of CVE-2022-37912?
The severity of CVE-2022-37912 is high with a score of 8.8.
Which software is affected by CVE-2022-37912?
Arubanetworks SD-WAN, Arubanetworks ArubaOS versions 6.5.4.0 to 6.5.4.22, Arubanetworks ArubaOS versions 8.4.0.0 to 8.6.0.17, Arubanetworks ArubaOS versions 8.7.0.0 to 8.7.1.9, Arubanetworks ArubaOS versions 8.8.0.0 to 10.3.0.1 are affected by CVE-2022-37912.
What is the impact of CVE-2022-37912?
The successful exploitation of CVE-2022-37912 allows an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Is there a fix available for CVE-2022-37912?
Yes, please refer to the official advisory from Aruba Networks for detailed instructions on how to apply the necessary patches or updates to mitigate CVE-2022-37912.