CVE-2023-37426

HIGH

EdgeConnect SD-WAN Orchestrator < 9.0.5 - Use of Hard-coded SSH Host Keys

Title source: llm
STIX 2.1

Description

EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.

References (1)

Core 1

Scores

CVSS v3 7.4
EPSS 0.0031
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (2)
arubanetworks/edgeconnect_sd-wan_orchestrator 9.3.0
arubanetworks/edgeconnect_sd-wan_orchestrator 9.0.0 - 9.0.5
Published Aug 22, 2023
Tracked Since Feb 18, 2026