8.8

CVE-2022-37903

A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.

Data is provided by the National Vulnerability Database (NVD)
ArubanetworksSd-wan Version >= 8.7.0.0-2.3.0.0 < 8.7.0.0-2.3.0.7
   Arubanetworks7005 Version-
   Arubanetworks7008 Version-
   Arubanetworks7010 Version-
   Arubanetworks7024 Version-
   Arubanetworks7030 Version-
   Arubanetworks7205 Version-
   Arubanetworks7210 Version-
   Arubanetworks7220 Version-
   Arubanetworks7240xm Version-
   Arubanetworks7280 Version-
ArubanetworksArubaos Version >= 6.5.4.0 < 6.5.4.23
   Arubanetworks7005 Version-
   Arubanetworks7008 Version-
   Arubanetworks7010 Version-
   Arubanetworks7024 Version-
   Arubanetworks7030 Version-
   Arubanetworks7205 Version-
   Arubanetworks7210 Version-
   Arubanetworks7220 Version-
   Arubanetworks7240xm Version-
   Arubanetworks7280 Version-
ArubanetworksArubaos Version >= 8.4.0.0 < 8.6.0.18
   Arubanetworks7005 Version-
   Arubanetworks7008 Version-
   Arubanetworks7010 Version-
   Arubanetworks7024 Version-
   Arubanetworks7030 Version-
   Arubanetworks7205 Version-
   Arubanetworks7210 Version-
   Arubanetworks7220 Version-
   Arubanetworks7240xm Version-
   Arubanetworks7280 Version-
ArubanetworksArubaos Version >= 8.7.0.0 < 8.7.1.10
   Arubanetworks7005 Version-
   Arubanetworks7008 Version-
   Arubanetworks7010 Version-
   Arubanetworks7024 Version-
   Arubanetworks7030 Version-
   Arubanetworks7205 Version-
   Arubanetworks7210 Version-
   Arubanetworks7220 Version-
   Arubanetworks7240xm Version-
   Arubanetworks7280 Version-
ArubanetworksArubaos Version >= 8.8.0.0 <= 8.9.0.3
   Arubanetworks7005 Version-
   Arubanetworks7008 Version-
   Arubanetworks7010 Version-
   Arubanetworks7024 Version-
   Arubanetworks7030 Version-
   Arubanetworks7205 Version-
   Arubanetworks7210 Version-
   Arubanetworks7220 Version-
   Arubanetworks7240xm Version-
   Arubanetworks7280 Version-
ArubanetworksArubaos Version10.3.0.0
   Arubanetworks7005 Version-
   Arubanetworks7008 Version-
   Arubanetworks7010 Version-
   Arubanetworks7024 Version-
   Arubanetworks7030 Version-
   Arubanetworks7205 Version-
   Arubanetworks7210 Version-
   Arubanetworks7220 Version-
   Arubanetworks7240xm Version-
   Arubanetworks7280 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.3% 0.527
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security-alert@hpe.com 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.