CVE-2022-37904

MEDIUM

ArubaOS 7xxx Controllers - Boot Sequence Remote Code Execution

Title source: manual
STIX 2.1

Description

Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

References (1)

Core 1

Scores

CVSS v3 6.6
EPSS 0.0075
EPSS Percentile 73.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-123
Status published
Products (3)
arubanetworks/arubaos 10.3.0.0
arubanetworks/arubaos 6.5.4.0 - 6.5.4.22
arubanetworks/sd-wan 8.7.0.0-2.3.0.0 - 8.7.0.0-2.3.0.6
Published Dec 12, 2022
Tracked Since Feb 18, 2026