CVE-2022-37914

CRITICALCVSS 9.8/10EPSS 1.33%

Last modified

CVE-2022-37914 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges leading to a complete compromise of the Aruba EdgeConnect Enterprise Orchestrator with versions 9.1.2.40051 and below, 9.0.7.40108 and below, 8.10.23.40009 and below, and any older branches of Orchestrator not specifically mentioned.. EPSS estimates a 1.33% chance of exploitation in the next 30 days.

Description

Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges leading to a complete compromise of the Aruba EdgeConnect Enterprise Orchestrator with versions 9.1.2.40051 and below, 9.0.7.40108 and below, 8.10.23.40009 and below, and any older branches of Orchestrator not specifically mentioned.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.33%

67.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
ArubanetworksAruba Edgeconnect Enterprise Orchestrator< 8.10.23.40009
ArubanetworksAruba Edgeconnect Enterprise Orchestrator>= 9.0.0, < 9.0.7.40108
ArubanetworksAruba Edgeconnect Enterprise Orchestrator>= 9.1.0, < 9.1.3.40197

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-37914?
Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these vulnerabilities could allow an attacker to gain administrative privileges leading to a complete compromise of the Aruba EdgeConnect Enterprise Orchestrator with versions 9.1.2.40051 and below, 9.0.7.40108 and below, 8.10.23.40009 and below, and any older branches of Orchestrator not specifically mentioned.
How severe is CVE-2022-37914?
CVE-2022-37914 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.33% probability of exploitation in the next 30 days.
How do I fix CVE-2022-37914?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-37914?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST