Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37906


An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of the vulnerability results in the ability to delete arbitrary files on the underlying operating system.


Published

2022-12-12T13:15:13.060

Last Modified

2025-05-02T19:15:51.983

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks sd-wan < 8.7.0.0-2.3.0.6 Yes
Operating System arubanetworks arubaos < 6.5.4.22 Yes
Operating System arubanetworks arubaos < 8.6.0.17 Yes
Operating System arubanetworks arubaos < 8.7.1.9 Yes
Operating System arubanetworks arubaos < 10.3.0.1 Yes

References