Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
CVE-2023-37422
What is CVE-2023-37422?
A vulnerability has been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator, allowing authenticated remote attackers to mount stored cross-site scripting (XSS) attacks. If exploited, this vulnerability can lead to the execution of arbitrary script code in the browser of an administrative user, posing significant security risks. Administrators must ensure proper security measures are in place to mitigate these types of attacks and safeguard the integrity of their web management systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x
EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x
EdgeConnect SD-WAN Orchestrator Orchestrator 9.2.x
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved