Description
An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking EdgeConnect SD-WANECOS 9.3.x.x: 9.3.3.0 and below – <=9.3.3.0
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking EdgeConnect SD-WANECOS 9.2.x.x: 9.2.9.0 and below – <=9.2.9.0
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking EdgeConnect SD-WANECOS 9.1.x.x: 9.1.11.0 and below – <=9.1.11.0
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking EdgeConnect SD-WANECOS 9.0.x.x: all builds are affected and are out of maintenance. – <=9.0.x.x
- Hewlett Packard Enterprise (HPE) / HPE Aruba Networking EdgeConnect SD-WANECOS 8.0.x.x: all builds are affected and are out of maintenance. – <=8.0.x.x