CVE-2022-43542: Code Injection
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43542?
CVE-2022-43542 is considered to be of high severity due to its potential for arbitrary command execution as root.
How do I fix CVE-2022-43542?
To mitigate CVE-2022-43542, users should update Aruba EdgeConnect Enterprise to the latest patched version provided by Aruba Networks.
What are the affected versions in CVE-2022-43542?
CVE-2022-43542 affects Aruba EdgeConnect Enterprise versions from 8.3.1.0 to 8.3.7.1, 9.0.0.0 to 9.0.7.0, 9.1.0.0 to 9.1.3.0, and 9.2.0.0 to 9.2.1.0.
Who can exploit CVE-2022-43542?
CVE-2022-43542 can be exploited by remote authenticated users who have access to the command line interface.
What are the potential impacts of CVE-2022-43542?
Exploiting CVE-2022-43542 could allow an attacker to execute arbitrary commands on the underlying operating system, leading to complete system compromise.