A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Ecos | — | Please note that due to the structure of this specific vulnerability HPE Aruba Networking has patched them only in the following software branches and versions of Orchestrator:
- Orchestrator 9.1.x: Orchestrator 9.1.10 (all builds) and above
- Orchestrator 9.2.x: Orchestrator 9.2.10 (all builds) and above
- Orchestrator 9.3.x: Orchestrator 9.3.3 (all builds) and above
- Orchestrator 9.4.x: Orchestrator 9.4.2 (all builds) and above
- Orchestrator 9.5.x: Orchestrator 9.5.0 (all builds) and above
Older branches and branches not specifically named
are not patched. Customers running an Orchestrator
release before 9.3.x should refer to these instructions:
https://www.arubanetworks.com/techdocs/sdwan-PDFs/docs/advisories/ec_adv_sec_settings_latest.pdf | Mar 17, 2025 | Jul 23, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub