CVE-2022-37897Critical· 9.8▾ MidnightThere is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitatio…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7arubaos >= 6.5.4.0, < 6.5.4.23arubaos >= 8.4.0.0, < 8.6.0.18arubaos >= 8.7.0.0, < 8.7.1.10arubaos >= 8.8.0.0, < 8.10.0.0arubaos = 10.3.0.0Upgrade past the affected range:
sd-wan 8.7.0.0-2.3.0.7arubaos 8.10.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37911Low· 3.8Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS
CVE-2022-37908Medium· 5.8An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers
CVE-2022-37909Medium· 5.3Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs
CVE-2022-37910Medium· 4.4A buffer overflow vulnerability exists in the ArubaOS command line interface
CVE-2022-37906Medium· 6.5An authenticated path traversal vulnerability exists in the ArubaOS command line interface