A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote attacker to perform command injection on certain CLI commands. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Ecos | — | HPE Aruba Networking recommends that customers upgrade their EdgeConnect SD-WAN Gateways to one of the following ECOS software versions to resolve this vulnerability: ECOS 9.4.5.0 and above, ECOS 9.5.5.0 and above. The main Resolution versions (ECOS 9.4.7.0, ECOS 9.5.7.0, ECOS 9.7.0.0 and above) also address this vulnerability. | Aug 20, 2026 | Jul 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub