Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37908


An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.


Published

2022-12-12T13:15:13.187

Last Modified

2025-05-02T19:15:52.323

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.8 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-494

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks sd-wan < 8.7.0.0-2.3.0.6 Yes
Operating System arubanetworks arubaos < 6.5.4.22 Yes
Operating System arubanetworks arubaos < 8.6.0.17 Yes
Operating System arubanetworks arubaos < 8.7.1.9 Yes
Operating System arubanetworks arubaos < 10.3.0.1 Yes
Hardware arubanetworks 7005 - No
Hardware arubanetworks 7008 - No
Hardware arubanetworks 7010 - No
Hardware arubanetworks 7024 - No
Hardware arubanetworks 7030 - No
Hardware arubanetworks 7205 - No
Hardware arubanetworks 7210 - No
Hardware arubanetworks 7220 - No
Hardware arubanetworks 7240xm - No
Hardware arubanetworks 7280 - No

References