CVE-2022-37901High· 7.2▾ TwilightAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying ope…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7arubaos >= 6.5.4.0, < 6.5.4.23arubaos >= 8.4.0.0, < 8.6.0.18arubaos >= 8.7.0.0, < 8.7.1.10arubaos >= 8.8.0.0, < 8.10.0.0arubaos = 10.3.0.0Upgrade past the affected range:
sd-wan 8.7.0.0-2.3.0.7arubaos 8.10.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37902High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37899High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37900High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37898High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37897Critical· 9.8There is a command injection vulnerability that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks AP management protocol) UDP port (8211)