CVE-2022-37924: OS Command Injection
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37924?
CVE-2022-37924 is classified as a critical vulnerability due to the potential for remote authenticated users to execute arbitrary commands as root.
How do I fix CVE-2022-37924?
To fix CVE-2022-37924, update the Aruba EdgeConnect Enterprise software to versions 8.3.7.1 or later, or 9.0.7.0 or later, or the respective higher versions.
Who is affected by CVE-2022-37924?
CVE-2022-37924 affects Aruba EdgeConnect Enterprise versions ranging from 8.3.1.0 to 8.3.7.1, 9.0.0.0 to 9.0.7.0, 9.1.0.0 to 9.1.3.0, and 9.2.0.0 to 9.2.1.0.
What kind of systems are vulnerable due to CVE-2022-37924?
CVE-2022-37924 poses a risk to systems running the Aruba EdgeConnect Enterprise command line interface.
Can CVE-2022-37924 be exploited remotely?
Yes, CVE-2022-37924 can be exploited by remote authenticated users, allowing them to execute arbitrary commands.