CVE-2022-37920: High severity arubanetworks edgeconnect enterprise vulnerability
Published Nov 30, 2022
·Updated
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Affected Software
4 affected components
Arubanetworks Edgeconnect Enterprise>=8.3.1.0<=8.3.7.1
Arubanetworks Edgeconnect Enterprise>=9.0.0.0<=9.0.7.0
Arubanetworks Edgeconnect Enterprise>=9.1.0.0<=9.1.3.0
Arubanetworks Edgeconnect Enterprise>=9.2.0.0<=9.2.1.0
Event History
Nov 30, 2022
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionSeverity