Remote Command Execution Flaw in Aruba EdgeConnect Enterprise Management Interface
CVE-2022-44533
Summary
A critical vulnerability in the Aruba EdgeConnect Enterprise web management interface permits authenticated remote users to execute arbitrary commands on the underlying host. This security flaw can lead to a complete system compromise, allowing attackers to gain root access to the operating system. Affected versions include ECOS 9.2.1.0 and earlier, and similar vulnerabilities exist in versions 9.1.3.0 and below, 9.0.7.0 and below, and 8.3.7.1 and below. Organizations utilizing affected products are strongly advised to apply security updates and protect their systems.
Affected Version(s)
Aruba EdgeConnect Enterprise Software ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below;
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved