cbcvebase.
CVE-2022-37909
published 2022-12-12

CVE-2022-37909: Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which…

PriorityP423medium5.3CVSS 3.1
AVAACHPRNUINSUCHINAN
EPSS
0.26%
17.4th percentile
Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.

Affected

5 ranges
VendorProductVersion rangeFixed in
arubanetworksarubaos>= 6.5.4.0 < 6.5.4.226.5.4.22
arubanetworksarubaos>= 8.4.0.0 < 8.6.0.178.6.0.17
arubanetworksarubaos>= 8.7.0.0 < 8.7.1.98.7.1.9
arubanetworksarubaos>= 8.8.0.0 < 10.3.0.110.3.0.1
arubanetworkssd-wan>= 8.7.0.0-2.3.0.0 < 8.7.0.0-2.3.0.68.7.0.0-2.3.0.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.