vulnerability
Aruba ECOS: CVE-2023-37426: Shared SSH Static Host Keys in EdgeConnect SD-WAN Orchestrator
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 9 | (AV:N/AC:M/Au:N/C:C/I:C/A:N) | Aug 22, 2023 | Mar 17, 2025 | Jul 3, 2025 |
Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:N)
Published
Aug 22, 2023
Added
Mar 17, 2025
Modified
Jul 3, 2025
Description
Self-hosted EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host. Orchestrator-as-a-Service (OaaS) instances are not affected by this vulnerability.
Solution
aruba-ecos-cve-2023-37426
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.