---
id: CVE-2022-37905
title: >-
  Vulnerabilities in ArubaOS running on 7xxx series controllers exist that
  allows an attacker to execute arbitrary code during the boot sequence
summary: >-
  Vulnerabilities in ArubaOS running on 7xxx series controllers exist that
  allows an attacker to execute arbitrary code during the boot sequence.
  Successful exploitation could allow an attacker to achieve permanent
  modification of the unde…
severity: medium
cvss: 6.6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-1236
vendor: arubanetworks
product: sd-wan
affected:
  - 'sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7'
  - 'arubaos >= 6.5.4.0, < 6.5.4.23'
  - 'arubaos >= 8.4.0.0, < 8.6.0.18'
  - 'arubaos >= 8.7.0.0, < 8.7.1.10'
  - 'arubaos >= 8.8.0.0, < 8.10.0.0'
  - arubaos = 10.3.0.0
patched:
  - sd-wan 8.7.0.0-2.3.0.7
  - arubaos 8.10.0.0
published: '2022-12-12'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T17:38:59.333'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-37905'
references:
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: security-alert@hpe.com
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00823
epssPercentile: 0.56069
ingestedAt: '2026-10-09T18:07:39.401Z'
---

## Overview

Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.



## Affected

- `sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7`
- `arubaos >= 6.5.4.0, < 6.5.4.23`
- `arubaos >= 8.4.0.0, < 8.6.0.18`
- `arubaos >= 8.7.0.0, < 8.7.1.10`
- `arubaos >= 8.8.0.0, < 8.10.0.0`
- `arubaos = 10.3.0.0`

## Remediation

Upgrade past the affected range:

- `sd-wan 8.7.0.0-2.3.0.7`
- `arubaos 8.10.0.0`
