First published: Wed Jul 24 2024(Updated: )
A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Edgeconnect SD-WAN Orchestrator |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33519 is a critical vulnerability that could allow an authenticated remote attacker to execute a server-side prototype pollution attack.
To fix CVE-2024-33519, update your HPE Aruba Networking EdgeConnect SD-WAN gateway to the latest patched version provided by the vendor.
CVE-2024-33519 affects the HPE Aruba Networking EdgeConnect SD-WAN gateway.
Yes, CVE-2024-33519 can be exploited by an authenticated remote attacker.
CVE-2024-33519 is associated with a server-side prototype pollution attack.