Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43518


An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.


Published

2022-12-12T13:15:14.857

Last Modified

2025-04-24T15:15:51.633

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks edgeconnect_enterprise ≤ 8.3.7.1 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.0.7.0 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.1.3.0 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.2.1.0 Yes

References