A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Ecos | — | Please note that due to the structure of
this specific vulnerability HPE Aruba Networking has
patched them only in the following software branches and versions of
Orchestrator:
- Orchestrator 9.3.x: Orchestrator 9.3.1 (all builds) and above
- Orchestrator 9.4.x: Orchestrator 9.4.0 (all builds) and above
- Orchestrator 9.5.x: Orchestrator 9.5.0 (all builds) and above
Older branches and branches not specifically named
are not patched. Customers running an Orchestrator
release before 9.3.x should refer to these instructions:
https://www.arubanetworks.com/techdocs/sdwan-PDFs/docs/advisories/ec_adv_sec_settings_latest.pdf | Mar 17, 2025 | Jul 23, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub