A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Ecos | — | Please note that due to the structure of this specific vulnerability HPE Aruba Networking has patched them only in the following software branches and versions of Orchestrator:
- Orchestrator 9.3.x: Orchestrator 9.3.1 (all builds) and above
- Orchestrator 9.4.x: Orchestrator 9.4.0 (all builds) and above
- Orchestrator 9.5.x: Orchestrator 9.5.0 (all builds) and above
Older branches and branches not specifically named
are not patched. Customers running an Orchestrator
release before 9.3.x should refer to these instructions:
https://www.arubanetworks.com/techdocs/sdwan-PDFs/docs/advisories/ec_adv_sec_settings_latest.pdf | Mar 17, 2025 | Jul 23, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub