First published: Thu Nov 03 2022(Updated: )
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Sd-wan | >=8.7.0.0-2.3.0.0<8.7.0.0-2.3.0.6 | |
Arubanetworks Arubaos | >=6.5.4.0<6.5.4.22 | |
Arubanetworks Arubaos | >=8.4.0.0<8.6.0.17 | |
Arubanetworks Arubaos | >=8.7.0.0<8.7.1.9 | |
Arubanetworks Arubaos | >=8.8.0.0<10.3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37912 is an authenticated command injection vulnerability in the ArubaOS command line interface.
The severity of CVE-2022-37912 is high with a score of 8.8.
Arubanetworks SD-WAN, Arubanetworks ArubaOS versions 6.5.4.0 to 6.5.4.22, Arubanetworks ArubaOS versions 8.4.0.0 to 8.6.0.17, Arubanetworks ArubaOS versions 8.7.0.0 to 8.7.1.9, Arubanetworks ArubaOS versions 8.8.0.0 to 10.3.0.1 are affected by CVE-2022-37912.
The successful exploitation of CVE-2022-37912 allows an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Yes, please refer to the official advisory from Aruba Networks for detailed instructions on how to apply the necessary patches or updates to mitigate CVE-2022-37912.