Vulnerabilities > Arubanetworks > Edgeconnect Enterprise

DATE CVE VULNERABILITY TITLE RISK
2022-12-12 CVE-2022-43542 Unspecified vulnerability in Arubanetworks Edgeconnect Enterprise
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host.
network
low complexity
arubanetworks
8.8
2022-12-12 CVE-2022-44532 Path Traversal vulnerability in Arubanetworks Edgeconnect Enterprise
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface.
network
low complexity
arubanetworks CWE-22
6.5
2022-12-12 CVE-2022-44533 Unspecified vulnerability in Arubanetworks Edgeconnect Enterprise
A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host.
network
low complexity
arubanetworks
7.2
2020-12-11 CVE-2020-12149 OS Command Injection vulnerability in Arubanetworks Edgeconnect Enterprise
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input.
network
low complexity
arubanetworks CWE-78
6.8
2020-12-11 CVE-2020-12148 OS Command Injection vulnerability in Arubanetworks Edgeconnect Enterprise
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance.
network
low complexity
arubanetworks CWE-78
6.8