CVE-2022-37926: XSS
A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface by uploading a specially crafted file. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-37926?
The severity of CVE-2022-37926 is classified as medium due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2022-37926?
To mitigate CVE-2022-37926, apply the latest security updates provided by Aruba Networks for EdgeConnect Enterprise.
What types of attacks can CVE-2022-37926 facilitate?
CVE-2022-37926 can facilitate stored cross-site scripting (XSS) attacks against users of the web management interface.
Which versions of EdgeConnect Enterprise are affected by CVE-2022-37926?
CVE-2022-37926 affects EdgeConnect Enterprise versions between 8.3.1.0 and 8.3.7.1, as well as versions between 9.0.0.0 and 9.0.7.0, and 9.1.0.0 to 9.1.3.0, and 9.2.0.0 to 9.2.1.0.
Who is at risk due to CVE-2022-37926?
Users of the web-based management interface of the affected EdgeConnect Enterprise versions are at risk due to CVE-2022-37926.