CVE-2022-44532: Path Traversal
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44532?
CVE-2022-44532 has a medium severity rating due to its potential impact on system confidentiality.
How do I fix CVE-2022-44532?
To mitigate CVE-2022-44532, upgrade to Aruba EdgeConnect Enterprise version 8.3.7.1 or later, 9.0.7.0 or later, 9.1.3.0 or later, or 9.2.1.0 or later.
What are the consequences of exploiting CVE-2022-44532?
Exploitation of CVE-2022-44532 allows unauthorized access to read arbitrary files on the underlying operating system, potentially exposing sensitive information.
Who is affected by CVE-2022-44532?
CVE-2022-44532 affects users of Aruba EdgeConnect Enterprise versions between 8.3.1.0 to 8.3.7.1, 9.0.0.0 to 9.0.7.0, 9.1.0.0 to 9.1.3.0, and 9.2.0.0 to 9.2.1.0.
Is authentication required to exploit CVE-2022-44532?
Yes, exploitation of CVE-2022-44532 requires authentication to the affected Aruba EdgeConnect Enterprise command line interface.