Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43542


Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.


Published

2022-12-12T13:15:14.977

Last Modified

2025-04-24T15:15:51.930

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks edgeconnect_enterprise ≤ 8.3.7.1 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.0.7.0 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.1.3.0 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.2.1.0 Yes

References