CVE-2022-37911XML External Entity (XXE) Injection in Arubaos

Severity
5.5MEDIUMNVD
CNA3.8
EPSS
0.3%
top 43.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:HExploitability: 1.2 | Impact: 4.2

Affected Packages2 packages

NVDarubanetworks/arubaos6.5.4.06.5.4.22+3
NVDarubanetworks/sd-wan8.7.0.0-2.3.0.08.7.0.0-2.3.0.6

🔴Vulnerability Details

2
GHSA
GHSA-2fwm-fp55-mv7p: Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS2022-12-12
CVEList
CVE-2022-37911: Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS2022-11-03
CVE-2022-37911 — XML External Entity (XXE) Injection | cvebase