Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
CVE-2023-37422

8.1HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
22 August 2023

Summary

A vulnerability has been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator, allowing authenticated remote attackers to mount stored cross-site scripting (XSS) attacks. If exploited, this vulnerability can lead to the execution of arbitrary script code in the browser of an administrative user, posing significant security risks. Administrators must ensure proper security measures are in place to mitigate these types of attacks and safeguard the integrity of their web management systems.

Affected Version(s)

EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x

EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x

EdgeConnect SD-WAN Orchestrator Orchestrator 9.2.x

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Jensen (@dozernz)
.