CVE-2022-37905

MEDIUM

ArubaOS <7xxx - RCE

Title source: llm
STIX 2.1

Description

Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

Scores

CVSS v3 6.6
EPSS 0.0171
EPSS Percentile 82.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1236
Status published
Products (3)
arubanetworks/arubaos 10.3.0.0
arubanetworks/arubaos 6.5.4.0 - 6.5.4.22
arubanetworks/sd-wan 8.7.0.0-2.3.0.0 - 8.7.0.0-2.3.0.6
Published Dec 12, 2022
Tracked Since Feb 18, 2026