HPE Aruba Networking EdgeConnect SD-WAN Orchestrator
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*
- 9.6.0
- 9.5.5
- 9.4.4
- ~9.3
- ~9.2
A SQL injection vulnerability has been identified in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN Orchestrator. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or manipulation. The issue affects EdgeConnect SD-WAN Orchestrator versions 9.5.5 and below, 9.4.4 and below, and 9.6.0, as well as all builds of versions 9.2.x and 9.3.x, which are end of life.
Exploitation of this vulnerability could allow an authenticated remote attacker to perform SQL injection attacks, executing arbitrary SQL commands on the database and potentially leading to unauthorized data access or manipulation.
Users are advised to upgrade to EdgeConnect SD-WAN Orchestrator version 9.6.1 and above or version 9.5.6 and above. For more information, visit the HPE Aruba Networking Support Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.