Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
CVE-2023-37422
8.1HIGH
Summary
A vulnerability has been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator, allowing authenticated remote attackers to mount stored cross-site scripting (XSS) attacks. If exploited, this vulnerability can lead to the execution of arbitrary script code in the browser of an administrative user, posing significant security risks. Administrators must ensure proper security measures are in place to mitigate these types of attacks and safeguard the integrity of their web management systems.
Affected Version(s)
EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x
EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x
EdgeConnect SD-WAN Orchestrator Orchestrator 9.2.x
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Daniel Jensen (@dozernz)