First published: Wed Jul 24 2024(Updated: )
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba Networks EdgeConnect SD-WAN | >=9.1.0<=9.1.9 | |
Aruba Networks EdgeConnect SD-WAN | >=9.2.0<=9.2.9 | |
Aruba Networks EdgeConnect SD-WAN | >=9.3.0<=9.3.2 | |
Aruba Networks EdgeConnect SD-WAN | >=9.4.0<=9.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-41914 has a severity rating that indicates a significant risk due to the potential for stored cross-site scripting (XSS) attacks.
To fix CVE-2024-41914, you should update the EdgeConnect SD-WAN Orchestrator to the latest version that addresses this vulnerability.
CVE-2024-41914 affects users of EdgeConnect SD-WAN Orchestrator versions 9.1.0 through 9.4.1.
CVE-2024-41914 is associated with stored cross-site scripting (XSS) attacks, which can be executed by authenticated remote attackers.
Yes, CVE-2024-41914 specifically targets administrative users through the web-based management interface.