HPE Aruba Networking EdgeConnect SD-WAN Gateways
cpe:2.3:h:silver-peak:unity_edgeconnect_sd-wan:*:*:*:*:*:*:*, +1 more
- >= 9.5.0.0, <= 9.5.3.0
- >= 9.4.0.0, <= 9.4.3.0
- ~9.3
- ~9.2
A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways allows remote authenticated users to execute arbitrary commands on the underlying host with root privileges. This issue affects EdgeConnect SD-WAN Release Streams 9.5.3.x and below, 9.4.3.x and below, and all versions of 9.2.x.x and older, which are out of maintenance.
Exploitation of this vulnerability allows for authenticated remote code execution as root on the underlying operating system.
Users are advised to upgrade to HPE Aruba Networking EdgeConnect SD-WAN versions 9.5.4.1 or 9.4.4.2. For EdgeConnect SD-WAN Orchestrator, the version must be equal to or greater than the ECOS version running on the gateways.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.