CVE-2022-37913
high-risk
Published 2022-10-28
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges leading to a complete compromise of the Aruba EdgeConnect Enterprise Orchestrator with versions 9.1.2.40051 and below, 9.0.7.40108 and below, 8.10.23.40009 and below, and any older branches of Orchestrator not specifically mentioned.
Do I need to act?
~
5.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (4)
Aruba Edgeconnect Enterprise Orchestrator
Aruba Edgeconnect Enterprise Orchestrator
Aruba Edgeconnect Enterprise Orchestrator
Aruba Edgeconnect Enterprise Orchestrator
Affected Vendors
References (2)
50
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
8/34 · Low
Exposure
10/34 · Low