HPE Aruba Networking EdgeConnect SD-WAN Orchestrator
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*
- 9.6.0
- 9.5.5
- 9.4.4
- ~9.3
- ~9.2
A vulnerability allowing authenticated remote attackers to perform SQL injection attacks has been identified in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. This vulnerability affects versions 9.5.5 and below, 9.4.4 and below, and all builds of versions 9.2.x and 9.3.x, which are end of life. Successful exploitation could enable attackers to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or manipulation.
Exploitation of this vulnerability could allow an authenticated remote attacker to execute arbitrary SQL commands on the database, with possible consequences of unauthorized data access or data manipulation.
Users are advised to upgrade to EdgeConnect SD-WAN Orchestrator version 9.6.1 and above or version 9.5.6 and above. For more information, visit the HPE Aruba Networking Support Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.