---
id: CVE-2022-37897
title: >-
  There is a command injection vulnerability that could lead to unauthenticated
  remote code execution by sending specially crafted packets destined to the
  PAPI (Aruba Networks AP management protocol) UDP port (8211)
summary: >-
  There is a command injection vulnerability that could lead to unauthenticated
  remote code execution by sending specially crafted packets destined to the
  PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful
  exploitatio…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
  - CWE-78
vendor: arubanetworks
product: sd-wan
affected:
  - 'sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7'
  - 'arubaos >= 6.5.4.0, < 6.5.4.23'
  - 'arubaos >= 8.4.0.0, < 8.6.0.18'
  - 'arubaos >= 8.7.0.0, < 8.7.1.10'
  - 'arubaos >= 8.8.0.0, < 8.10.0.0'
  - arubaos = 10.3.0.0
patched:
  - sd-wan 8.7.0.0-2.3.0.7
  - arubaos 8.10.0.0
published: '2022-12-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T17:11:44.020'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-37897'
references:
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: security-alert@hpe.com
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01755
epssPercentile: 0.77248
ingestedAt: '2026-10-08T17:56:11.692Z'
---

## Overview

There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.



## Affected

- `sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7`
- `arubaos >= 6.5.4.0, < 6.5.4.23`
- `arubaos >= 8.4.0.0, < 8.6.0.18`
- `arubaos >= 8.7.0.0, < 8.7.1.10`
- `arubaos >= 8.8.0.0, < 8.10.0.0`
- `arubaos = 10.3.0.0`

## Remediation

Upgrade past the affected range:

- `sd-wan 8.7.0.0-2.3.0.7`
- `arubaos 8.10.0.0`
