Security News > 2022 > October > Aruba fixes critical RCE and auth bypass flaws in EdgeConnect

Aruba has released security updates for the EdgeConnect Enterprise Orchestrator, addressing multiple critical severity vulnerabilities that enable remote attackers to compromise the host.
Aruba EdgeConnect Orchestrator is a widely used WAN management solution, offering enterprise users optimization, administration, automation, and real-time visibility and monitoring features.
CVE-2022-37913 and CVE-2022-37914: Authentication bypass flaw in the web-based management interface of EdgeConnect Orchestrator, allowing an unauthenticated, remote attacker to bypass authentication.
CVE-2022-37915: Flaw in the web-based management interface of EdgeConnect Orchestrator, allowing arbitrary command execution on the underlying host and leading to complete system compromise.
Aruba has noted that, as of today, it has not detected active exploitation of the mentioned flaws and has seen no discussions or proof of concept exploits that target the vulnerabilities.
Considering the criticality of the flaws and broad deployment of EdgeConnect in valuable environments, it's safe to suggest that attackers will attempt to create exploits for the vulnerabilities.
News URL
Related news
- Unpatched critical bugs in Versa Concerto lead to auth bypass, RCE (source)
- Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability (source)
- Critical Erlang/OTP SSH pre-auth RCE is 'Surprisingly Easy' to exploit, patch now (source)
- ASUS warns of critical auth bypass flaw in routers using AiCloud (source)
- Critical Erlang/OTP SSH RCE bug now has public exploits, patch now (source)
- Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028) (source)
- Critical Langflow RCE flaw exploited to hack AI app servers (source)
- SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version (source)
- Ivanti warns of critical Neurons for ITSM auth bypass flaw (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-10-28 | CVE-2022-37915 | Unspecified vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. | 9.8 |
2022-10-28 | CVE-2022-37914 | Unspecified vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. | 9.8 |
2022-10-28 | CVE-2022-37913 | Unspecified vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. | 9.8 |