Edgeconnect Sd Wan Orchestrator Aruba Networks Edgeconnect Sd Wan Orchestrator

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Aruba Networks Edgeconnect Sd Wan Orchestrator.

By the Year

In 2026 there have been 0 vulnerabilities in Aruba Networks Edgeconnect Sd Wan Orchestrator. Edgeconnect Sd Wan Orchestrator did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 4 8.18
2023 20 6.92

It may take a day or so for new Edgeconnect Sd Wan Orchestrator vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Aruba Networks Edgeconnect Sd Wan Orchestrator Security Vulnerabilities

Command Injection in HPE Aruba EdgeConnect SD-WAN CLI
CVE-2024-41136 8.8 - High - July 24, 2024

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

Shell injection

EdgeConnect Orchestrator Reflected XSS in Web UI
CVE-2024-22444 6.1 - Medium - July 24, 2024

A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.

XSS

EdgeConnect SD-WAN Orchestrator Prototype Pollution Enables OS Command Exec
CVE-2024-22443 8.8 - High - July 24, 2024

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Prototype Pollution

EdgeConnect SDWAN Orchestrator Authenticated Admin XSS to Execute Scripts
CVE-2024-41914 9 - Critical - July 24, 2024

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

XSS

SQLi in EdgeConnect SD-WAN Orchestrator WebMgmt Interface
CVE-2023-37432 8.1 - High - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

EdgeConnect SD-WAN Orchestrator Shared SSH Key Spoofing
CVE-2023-37426 7.5 - High - August 22, 2023

EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.

Use of Hard-coded Credentials

EdgeConnect SD-WAN Orchestrator Stored XSS in Web Admin Interface
CVE-2023-37425 6.1 - Medium - August 22, 2023

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

XSS

EdgeConnect SD-WAN Orchestrator Web UI Auth RCE
CVE-2023-37427 7.2 - High - August 22, 2023

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

EdgeConnect SD-WAN Orchestrator RCE via Authenticated Web UI
CVE-2023-37428 7.2 - High - August 22, 2023

A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.

Directory traversal

EdgeConnect SDWAN Orchestrator WebUI SQL Injection
CVE-2023-37429 8.1 - High - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

SQLi in EdgeConnect SD-WAN Orchestrator Web UI
CVE-2023-37430 8.1 - High - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

SQL Injection in EdgeConnect SD-WAN Orchestrator Web Management Interface
CVE-2023-37431 8.1 - High - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

SQLi in EdgeConnect SD-WAN Orchestrator Web UI
CVE-2023-37437 6.5 - Medium - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

EdgeConnect SD-WAN Orchestrator Auth SQL Injection via Web UI
CVE-2023-37433 8.1 - High - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

SQL Injection via Authenticated Remote Access in Fortinet EdgeConnect SD-WAN
CVE-2023-37434 8.1 - High - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

EdgeConnect SDWAN Orchestrator XSS via Web UI Stored XSS
CVE-2023-37422 5.4 - Medium - August 22, 2023

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

XSS

Stored XSS in EdgeConnect SD-WAN Orchestrator Web UI
CVE-2023-37423 5.4 - Medium - August 22, 2023

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

XSS

EdgeConnect SD-WAN Orchestrator: Unauth REM Command Exec
CVE-2023-37424 8.1 - High - August 22, 2023

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

EdgeConnect SD-WAN XSS in Admin Interface Allows Authenticated Attack
CVE-2023-37421 5.4 - Medium - August 22, 2023

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

XSS

EdgeConnect SD-WAN Orchestrator: Authenticated SQLi via Web UI
CVE-2023-37438 6.5 - Medium - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

EdgeConnect SD-WAN Orchestrator Authenticated Web UI SQLi
CVE-2023-37439 6.1 - Medium - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

XSS

EdgeConnect SD-WAN Orchestrator SSRF via Web UI Allow Unauth SSRF Leak
CVE-2023-37440 5.3 - Medium - August 22, 2023

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal     structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information.

SSRF

SQLi in Palo Alto EdgeConnect SD-WAN Orchestrator Web UI Authenticated Attack
CVE-2023-37435 6.5 - Medium - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

SQLi in EdgeConnect SDWAN Orchestrator Web UI
CVE-2023-37436 6.5 - Medium - August 22, 2023

Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to     obtain and modify sensitive information in the underlying database potentially leading to the exposure and corruption of sensitive data controlled by the EdgeConnect SD-WAN Orchestrator host.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Aruba Networks Edgeconnect Sd Wan Orchestrator or by Aruba Networks? Click the Watch button to subscribe.

subscribe