CVE-2022-43541: Code Injection
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43541?
CVE-2022-43541 is considered a critical vulnerability due to its potential to allow remote authenticated users to execute arbitrary commands as root.
How do I fix CVE-2022-43541?
To fix CVE-2022-43541, update the Aruba EdgeConnect Enterprise software to the latest patched version provided by Aruba Networks.
Which versions are affected by CVE-2022-43541?
CVE-2022-43541 affects Aruba EdgeConnect Enterprise versions between 8.3.1.0 and 8.3.7.1, as well as 9.0.0.0 to 9.0.7.0, 9.1.0.0 to 9.1.3.0, and 9.2.0.0 to 9.2.1.0.
What could an attacker achieve by exploiting CVE-2022-43541?
Exploiting CVE-2022-43541 could allow an attacker to gain full control of the underlying operating system by executing arbitrary commands as root.
Who is affected by CVE-2022-43541?
Organizations using vulnerable versions of Aruba EdgeConnect Enterprise are at risk due to CVE-2022-43541.