Vulnerabilities > Arubanetworks > SD WAN > High

DATE CVE VULNERABILITY TITLE RISK
2022-12-12 CVE-2022-37905 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence.
network
low complexity
arubanetworks
8.8
2022-12-12 CVE-2022-37906 Path Traversal vulnerability in Arubanetworks Arubaos and Sd-Wan
An authenticated path traversal vulnerability exists in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-22
8.1
2022-12-12 CVE-2022-37907 Unspecified vulnerability in Arubanetworks Arubaos and Sd-Wan
A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system.
network
low complexity
arubanetworks
7.5
2022-12-12 CVE-2022-37912 OS Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface.
network
low complexity
arubanetworks CWE-78
8.8
2021-09-07 CVE-2021-37725 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
A remote cross-site request forgery (csrf) vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.4-2.2.0.4; Prior to 8.8.0.1, 8.7.1.2, 8.6.0.8, 8.5.0.12, 8.3.0.15.
8.8
2021-09-07 CVE-2021-37731 Path Traversal vulnerability in multiple products
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Software version(s): Prior to 8.6.0.0-2.2.0.4; Prior to 8.7.1.1, 8.6.0.7, 8.5.0.12, 8.3.0.16.
local
low complexity
arubanetworks siemens CWE-22
7.2