← Voltar para CVEs
CVE-2022-37893
HIGH7.8
Descricao
An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.
Detalhes CVE
Pontuacao CVSS v3.17.8
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado10/7/2022
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
arubanetworks:arubaosarubanetworks:instantsiemens:scalance_w1750dsiemens:scalance_w1750d_firmware
Fraquezas (CWE)
CWE-78
Referencias
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf(security-alert@hpe.com)
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-014.txt(security-alert@hpe.com)
https://cert-portal.siemens.com/productcert/pdf/ssa-506569.pdf(af854a3a-2127-422b-91ae-364da2661108)
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-014.txt(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.