CVE-2022-37909Medium· 5.3▾ SunlitAruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.
sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7arubaos >= 6.5.4.0, < 6.5.4.23arubaos >= 8.4.0.0, < 8.6.0.18arubaos >= 8.7.0.0, < 8.7.1.10arubaos >= 8.8.0.0, < 8.10.0.0arubaos = 10.3.0.0Upgrade past the affected range:
sd-wan 8.7.0.0-2.3.0.7arubaos 8.10.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37911Low· 3.8Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37908Medium· 5.8An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers
CVE-2022-37910Medium· 4.4A buffer overflow vulnerability exists in the ArubaOS command line interface
CVE-2022-37906Medium· 6.5An authenticated path traversal vulnerability exists in the ArubaOS command line interface
CVE-2022-37907Medium· 5.8A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system