---
id: CVE-2022-37910
title: A buffer overflow vulnerability exists in the ArubaOS command line interface
summary: >+
  A buffer overflow vulnerability exists in the ArubaOS command line interface.
  Successful exploitation of this vulnerability results in a denial of service
  on the affected system.

severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
  - CWE-120
vendor: arubanetworks
product: sd-wan
affected:
  - 'sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7'
  - 'arubaos >= 6.5.4.0, < 6.5.4.23'
  - 'arubaos >= 8.4.0.0, < 8.6.0.18'
  - 'arubaos >= 8.7.0.0, < 8.7.1.10'
  - 'arubaos >= 8.8.0.0, < 8.10.0.0'
  - arubaos = 10.3.0.0
patched:
  - sd-wan 8.7.0.0-2.3.0.7
  - arubaos 8.10.0.0
published: '2022-12-12'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T17:14:03.923'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-37910'
references:
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: security-alert@hpe.com
  - url: 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00607
epssPercentile: 0.47421
ingestedAt: '2026-10-08T17:56:11.694Z'
---

## Overview

A buffer overflow vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in a denial of service on the affected system.



## Affected

- `sd-wan >= 8.5.0.0-2.1.0.0, < 8.7.0.0-2.3.0.7`
- `arubaos >= 6.5.4.0, < 6.5.4.23`
- `arubaos >= 8.4.0.0, < 8.6.0.18`
- `arubaos >= 8.7.0.0, < 8.7.1.10`
- `arubaos >= 8.8.0.0, < 8.10.0.0`
- `arubaos = 10.3.0.0`

## Remediation

Upgrade past the affected range:

- `sd-wan 8.7.0.0-2.3.0.7`
- `arubaos 8.10.0.0`
