vulnerability

Aruba ECOS: CVE-2023-37426: Shared SSH Static Host Keys in EdgeConnect SD-WAN Orchestrator

Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:N)
Published
Aug 22, 2023
Added
Mar 17, 2025
Modified
Jul 3, 2025

Description

Self-hosted EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host. Orchestrator-as-a-Service (OaaS) instances are not affected by this vulnerability.

Solution

aruba-ecos-cve-2023-37426
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.