HPE Aruba Networking EdgeConnect SD-WAN Orchestrator
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*
- 9.6.0
- 9.5.5
- 9.4.4
- ~9.3
- ~9.2
An authenticated remote SQL injection vulnerability has been identified in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. This vulnerability affects versions 9.5.5 and below, 9.4.4 and below, and all builds of versions 9.2.x and 9.3.x, which are end of maintenance. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, leading to unauthorized data access or manipulation.
Exploitation of this vulnerability could result in unauthorized access to or manipulation of data in the application's database.
Users are advised to upgrade to EdgeConnect SD-WAN Orchestrator version 9.6.1 and above or version 9.5.6 and above. For assistance, contact HPE Services - Aruba Networking.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.