Stored Cross-Site Scripting (XSS) Vulnerability in EdgeConnect SD-WAN Orchestrator
CVE-2024-41914
Key Information:
- Vendor
HP
- Vendor
- CVE Published:
- 24 July 2024
What is CVE-2024-41914?
A vulnerability exists in the web-based management interface of HPE's EdgeConnect SD-WAN Orchestrator, which can be exploited by an authenticated remote attacker to initiate a stored cross-site scripting (XSS) attack. This flaw allows the execution of arbitrary script code in the browser of an administrative user interacting with the affected interface. The dynamic nature of the web-based interface may allow the attacker to store malicious scripts, which are then executed whenever an administrator accesses the compromised section. Proper security measures and updates are necessary to mitigate this potential risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HPE Aruba Networking EdgeConnect SD-WAN Orchestrator EdgeConnect SD-WAN Orchestrator 9.4.x: Orchestrator 9.4.1 (all builds) and below
HPE Aruba Networking EdgeConnect SD-WAN Orchestrator EdgeConnect SD-WAN Orchestrator 9.3.x: Orchestrator 9.3.2 (all builds) and below
HPE Aruba Networking EdgeConnect SD-WAN Orchestrator EdgeConnect SD-WAN Orchestrator 9.2.x: Orchestrator 9.2.9 (all builds) and below
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved