Authenticated Remote Code Execution via Path Traversal in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
CVE-2023-37428

7.2HIGH

Key Information:

Vendor
HP
Vendor
CVE Published:
22 August 2023

Summary

A vulnerability in the web management interface of the EdgeConnect SD-WAN Orchestrator enables remote authenticated users to execute arbitrary commands on the host operating system. This flaw poses a significant risk as it can result in complete system compromise, granting attackers root access. Immediate action is recommended to mitigate potential threats.

Affected Version(s)

EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x

EdgeConnect SD-WAN Orchestrator Orchestrator 9.3.x

EdgeConnect SD-WAN Orchestrator Orchestrator 9.2.x

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Jensen (@dozernz)
.