CVE-2022-37903High· 7.2▾ TwilightA vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlyin…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.
sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7arubaos >= 6.5.4.0, < 6.5.4.23arubaos >= 8.4.0.0, < 8.6.0.18arubaos >= 8.7.0.0, < 8.7.1.10arubaos >= 8.8.0.0, < 8.10.0.0arubaos = 10.3.0.0Upgrade past the affected range:
sd-wan 8.7.0.0-2.3.0.7arubaos 8.10.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37905Medium· 6.6Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence
CVE-2022-37902High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37904Medium· 6.6Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence
CVE-2022-37899High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37900High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37901High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface