← Back to CVEs
CVE-2022-37893
HIGH7.8
Description
An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.
CVE Details
CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published10/7/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
arubanetworks:arubaosarubanetworks:instantsiemens:scalance_w1750dsiemens:scalance_w1750d_firmware
Weaknesses (CWE)
CWE-78
References
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf(security-alert@hpe.com)
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-014.txt(security-alert@hpe.com)
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-014.txt(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.