First published: Tue Aug 22 2023(Updated: )
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information.
Credit: security-alert@hpe.com security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Edgeconnect Sd-wan Orchestrator | <9.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37440 is a vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator that allows an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack.
The severity of CVE-2023-37440 is medium with a CVSS severity score of 5.5.
An attacker can exploit CVE-2023-37440 by sending crafted requests to the web-based management interface of EdgeConnect SD-WAN Orchestrator.
The affected software by CVE-2023-37440 is Arubanetworks Edgeconnect Sd-wan Orchestrator version up to 9.3.1.
Yes, upgrading to a version higher than 9.3.1 of Arubanetworks Edgeconnect Sd-wan Orchestrator resolves the vulnerability.