First published: Wed Nov 30 2022(Updated: )
A vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based management interface to create a denial-of-service condition which prevents the appliance from properly responding to API requests in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below;
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Edgeconnect Enterprise | >=8.3.1.0<=8.3.7.1 | |
Arubanetworks Edgeconnect Enterprise | >=9.0.0.0<=9.0.7.0 | |
Arubanetworks Edgeconnect Enterprise | >=9.1.0.0<=9.1.3.0 | |
Arubanetworks Edgeconnect Enterprise | >=9.2.0.0<=9.2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-37919.
The severity of CVE-2022-37919 is high with a score of 7.5.
Aruba EdgeConnect Enterprise versions 8.3.1.0 to 8.3.7.1, 9.0.0.0 to 9.0.7.0, 9.1.0.0 to 9.1.3.0, and 9.2.0.0 to 9.2.1.0 are affected by CVE-2022-37919.
An unauthenticated attacker can exploit CVE-2022-37919 by using the web-based management interface to create a denial-of-service condition, which prevents the Aruba EdgeConnect Enterprise appliance from properly responding to API requests.
Apply the latest security patch or update provided by Aruba Networks to fix CVE-2022-37919.