CVE-2022-37919: High severity arubanetworks edgeconnect enterprise vulnerability
A vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based management interface to create a denial-of-service condition which prevents the appliance from properly responding to API requests in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below;
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-37919.
What is the severity of CVE-2022-37919?
The severity of CVE-2022-37919 is high with a score of 7.5.
Which software versions of Aruba EdgeConnect Enterprise are affected by CVE-2022-37919?
Aruba EdgeConnect Enterprise versions 8.3.1.0 to 8.3.7.1, 9.0.0.0 to 9.0.7.0, 9.1.0.0 to 9.1.3.0, and 9.2.0.0 to 9.2.1.0 are affected by CVE-2022-37919.
How can an attacker exploit CVE-2022-37919?
An unauthenticated attacker can exploit CVE-2022-37919 by using the web-based management interface to create a denial-of-service condition, which prevents the Aruba EdgeConnect Enterprise appliance from properly responding to API requests.
How can I fix CVE-2022-37919?
Apply the latest security patch or update provided by Aruba Networks to fix CVE-2022-37919.