PT-2022-27225 · Aruba · Aruba Edgeconnect Enterprise

Published

2022-11-30

·

Updated

2022-12-14

·

CVE-2022-44532

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Aruba EdgeConnect Enterprise Software versions prior to ECOS 9.2.1.0 Aruba EdgeConnect Enterprise Software versions prior to ECOS 9.1.3.0 Aruba EdgeConnect Enterprise Software versions prior to ECOS 9.0.7.0 Aruba EdgeConnect Enterprise Software versions prior to ECOS 8.3.7.1
Description An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Recommendations For versions prior to ECOS 9.2.1.0, update to a version above ECOS 9.2.1.0 to resolve the issue. For versions prior to ECOS 9.1.3.0, update to a version above ECOS 9.1.3.0 to resolve the issue. For versions prior to ECOS 9.0.7.0, update to a version above ECOS 9.0.7.0 to resolve the issue. For versions prior to ECOS 8.3.7.1, update to a version above ECOS 8.3.7.1 to resolve the issue. As a temporary workaround, consider restricting access to the command line interface until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-44532

Affected Products

Aruba Edgeconnect Enterprise