Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-37440


A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal     structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information.


Published

2023-08-22T19:16:38.907

Last Modified

2024-11-21T08:11:42.970

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-918
  • Type: Secondary
    CWE-918

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks edgeconnect_sd-wan_orchestrator < 9.3.1 Yes

References