CVE-2022-37921: High severity arubanetworks edgeconnect enterprise vulnerability
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37921?
CVE-2022-37921 has a high severity rating due to potential root command execution by authenticated users.
How do I fix CVE-2022-37921?
To mitigate CVE-2022-37921, update Aruba EdgeConnect Enterprise to the latest patched version recommended by Aruba Networks.
Who is affected by CVE-2022-37921?
CVE-2022-37921 affects Aruba EdgeConnect Enterprise versions between 8.3.1.0 and 8.3.7.1, 9.0.0.0 and 9.0.7.0, 9.1.0.0 and 9.1.3.0, and 9.2.0.0 and 9.2.1.0.
What kind of impact can CVE-2022-37921 have?
A successful exploit of CVE-2022-37921 can lead to arbitrary command execution as root, compromising the underlying operating system.
Is CVE-2022-37921 being actively exploited?
There are no confirmed reports of active exploitation for CVE-2022-37921, but the vulnerability poses a significant risk if unpatched.