First published: Wed Jul 24 2024(Updated: )
A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba Networks EdgeConnect SD-WAN | >=9.1.0<=9.1.9 | |
Aruba Networks EdgeConnect SD-WAN | >=9.2.0<=9.2.9 | |
Aruba Networks EdgeConnect SD-WAN | >=9.3.0<9.3.3 | |
Aruba Networks EdgeConnect SD-WAN | >=9.4.0<9.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-22444 has a high severity rating due to its potential to allow a remote attacker to conduct reflected cross-site scripting (XSS) attacks.
To fix CVE-2024-22444, upgrade the EdgeConnect SD-WAN Orchestrator to a version beyond the vulnerable ranges, specifically to 9.1.9 or later, 9.2.9 or later, 9.3.3 or later, or 9.4.2 or later.
CVE-2024-22444 affects specific versions of the EdgeConnect SD-WAN Orchestrator running versions between 9.1.0 and 9.1.9, between 9.2.0 and 9.2.9, between 9.3.0 and 9.3.3, and between 9.4.0 and 9.4.2.
Administrators and users of the EdgeConnect SD-WAN Orchestrator are the primary individuals affected by CVE-2024-22444.
Failure to address CVE-2024-22444 could permit attackers to execute arbitrary scripts in the context of users' browsers, leading to potential data theft or unauthorized actions.