PT-2022-26954 · Aruba · Aruba Edgeconnect Enterprise

Published

2022-11-30

·

Updated

2022-12-15

·

CVE-2022-43518

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Aruba EdgeConnect Enterprise Software versions prior to ECOS 9.2.1.0 Aruba EdgeConnect Enterprise Software versions prior to ECOS 9.1.3.0 Aruba EdgeConnect Enterprise Software versions prior to ECOS 9.0.7.0 Aruba EdgeConnect Enterprise Software versions prior to ECOS 8.3.7.1
Description An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Recommendations For versions prior to ECOS 9.2.1.0, update to a version above ECOS 9.2.1.0 to resolve the issue. For versions prior to ECOS 9.1.3.0, update to a version above ECOS 9.1.3.0 to resolve the issue. For versions prior to ECOS 9.0.7.0, update to a version above ECOS 9.0.7.0 to resolve the issue. For versions prior to ECOS 8.3.7.1, update to a version above ECOS 8.3.7.1 to resolve the issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-43518

Affected Products

Aruba Edgeconnect Enterprise