Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
CVE-2023-37423

8.1HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
22 August 2023

Summary

The web-based management interface of EdgeConnect SD-WAN Orchestrator contains vulnerabilities that may allow an authenticated remote attacker to execute a stored cross-site scripting (XSS) attack on an administrative user. When exploited, this vulnerability enables the attacker to run arbitrary script code in the victim's browser, potentially compromising sensitive information or furthering intrusion attempts within the affected environment.

Affected Version(s)

EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x

EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x

EdgeConnect SD-WAN Orchestrator Orchestrator 9.2.x

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Jensen (@dozernz)
.