First published: Tue Aug 22 2023(Updated: )
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.
Credit: security-alert@hpe.com security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Edgeconnect Sd-wan Orchestrator | >=9.0.0<=9.0.5 | |
Arubanetworks Edgeconnect Sd-wan Orchestrator | >=9.1.0<=9.1.7 | |
Arubanetworks Edgeconnect Sd-wan Orchestrator | >=9.2.0<=9.2.5 | |
Arubanetworks Edgeconnect Sd-wan Orchestrator | =9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this advisory is CVE-2023-37426.
The severity of CVE-2023-37426 is high with a score of 7.4.
The affected software for CVE-2023-37426 is Arubanetworks Edgeconnect Sd-wan Orchestrator versions prior to 9.3.0.
CVE-2023-37426 allows an attacker to spoof the SSH host signature and masquerade as a legitimate Orchestrator host.
To fix CVE-2023-37426, update your Arubanetworks Edgeconnect Sd-wan Orchestrator to version 9.3.0 or higher.