---
id: CVE-2022-37909
title: >-
  Aruba has identified certain configurations of ArubaOS that can lead to
  sensitive information disclosure from the configured ESSIDs
summary: >-
  Aruba has identified certain configurations of ArubaOS that can lead to
  sensitive information disclosure from the configured ESSIDs. The scenarios in
  which disclosure of potentially sensitive information can occur are complex,
  and depend…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
vendor: arubanetworks
product: sd-wan
affected:
  - 'sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7'
  - 'arubaos >= 6.5.4.0, < 6.5.4.23'
  - 'arubaos >= 8.4.0.0, < 8.6.0.18'
  - 'arubaos >= 8.7.0.0, < 8.7.1.10'
  - 'arubaos >= 8.8.0.0, < 8.10.0.0'
  - arubaos = 10.3.0.0
patched:
  - sd-wan 8.7.0.0-2.3.0.7
  - arubaos 8.10.0.0
published: '2022-12-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T17:13:42.140'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-37909'
references:
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: security-alert@hpe.com
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00267
epssPercentile: 0.17306
ingestedAt: '2026-10-08T17:56:11.694Z'
---

## Overview

Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.



## Affected

- `sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7`
- `arubaos >= 6.5.4.0, < 6.5.4.23`
- `arubaos >= 8.4.0.0, < 8.6.0.18`
- `arubaos >= 8.7.0.0, < 8.7.1.10`
- `arubaos >= 8.8.0.0, < 8.10.0.0`
- `arubaos = 10.3.0.0`

## Remediation

Upgrade past the affected range:

- `sd-wan 8.7.0.0-2.3.0.7`
- `arubaos 8.10.0.0`
