CVE-2022-37904Medium· 6.6▾ SunlitVulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the unde…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7arubaos >= 6.5.4.0, < 6.5.4.23arubaos >= 8.4.0.0, < 8.6.0.18arubaos >= 8.7.0.0, < 8.7.1.10arubaos >= 8.8.0.0, < 8.10.0.0arubaos = 10.3.0.0Upgrade past the affected range:
sd-wan 8.7.0.0-2.3.0.7arubaos 8.10.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37905Medium· 6.6Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence
CVE-2022-37902High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37903High· 7.2A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface
CVE-2022-37899High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37900High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37901High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface