Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22443


A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.


Published

2024-07-24T15:15:11.370

Last Modified

2024-11-21T08:56:18.113

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-1321
  • Type: Secondary
    CWE-1321

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks edgeconnect_sd-wan_orchestrator < 9.1.10 Yes
Application arubanetworks edgeconnect_sd-wan_orchestrator < 9.2.10 Yes
Application arubanetworks edgeconnect_sd-wan_orchestrator < 9.3.3 Yes
Application arubanetworks edgeconnect_sd-wan_orchestrator < 9.4.2 Yes

References