CVE-2022-37903Out-of-bounds Write in Arubaos

Severity
8.8HIGHNVD
CNA7.2
EPSS
0.5%
top 33.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDarubanetworks/sd-wan8.7.0.0-2.3.0.08.7.0.0-2.3.0.7
NVDarubanetworks/arubaos6.5.4.06.5.4.23+4

🔴Vulnerability Details

2
GHSA
GHSA-4c26-7c6w-x9h2: A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface2022-12-12
CVEList
CVE-2022-37903: A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface2022-11-03
CVE-2022-37903 — Out-of-bounds Write in Arubaos | cvebase