Arubanetworks Edgeconnect Sd-Wan Orchestrator vulnerabilities
67 known vulnerabilities affecting arubanetworks/edgeconnect_sd-wan_orchestrator.
Total CVEs
67
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH33MEDIUM26
Vulnerabilities
Page 2 of 4
CVE-2026-76691P3HIGHCVSS 7.2≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76691 [HIGH] CWE-120 CVE-2026-76691: Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gatew
Buffer overflow vulnerabilities exist in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker to execute arbitrary commands as a privileged user on the underlying operating system.
nvd
CVE-2026-76679P3HIGHCVSS 8.6≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76679 [HIGH] CWE-400 CVE-2026-76679: Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacen
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct denial-of-service attacks. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
nvd
CVE-2026-76690P3HIGHCVSS 7.2≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76690 [HIGH] CWE-78 CVE-2026-76690: A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may all
A vulnerability exists in a component of the HPE Networking EdgeConnect SD-WAN Gateways that may allow for arbitrary command execution. An authenticated remote attacker could exploit this vulnerability by providing a specially crafted input to the affected component. Successful exploitation could result in remote code execution as root.
nvd
CVE-2026-76689P3HIGHCVSS 7.2≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76689 [HIGH] CWE-121 CVE-2026-76689: A vulnerability exists in the configuration processing logic of the affected component where malform
A vulnerability exists in the configuration processing logic of the affected component where malformed input is improperly processed. An authenticated remote attacker with administrative privileges could exploit this vulnerability by providing specially crafted configuration data. Successful exploitation could result in a stack-based buffer overflow,
nvd
CVE-2023-37434P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37434 [HIGH] CWE-89 CVE-2023-37434: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database potent
nvd
CVE-2023-37432P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37432 [HIGH] CWE-89 CVE-2023-37432: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database potent
nvd
CVE-2023-37429P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37429 [HIGH] CWE-89 CVE-2023-37429: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database potent
nvd
CVE-2023-37431P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37431 [HIGH] CWE-89 CVE-2023-37431: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database potent
nvd
CVE-2023-37430P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37430 [HIGH] CWE-89 CVE-2023-37430: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database potent
nvd
CVE-2023-37433P3HIGHCVSS 8.1≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37433 [HIGH] CWE-89 CVE-2023-37433: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database potent
nvd
CVE-2026-76698P3MEDIUMCVSS 6.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76698 [MEDIUM] CWE-77 CVE-2026-76698: A command injection vulnerability exists in the web-based management interface of HPE Networking Edg
A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways. An authenticated remote attacker with limited access privileges could exploit this vulnerability through specially crafted input. Successful exploitation, under certain conditions, could result in the execution of arbitrary co
nvd
CVE-2023-37427P3HIGHCVSS 7.2≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37427 [HIGH] CWE-94 CVE-2023-37427: A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compr
nvd
CVE-2026-76688P3HIGHCVSS 7.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76688 [HIGH] CWE-287 CVE-2026-76688: Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orc
Vulnerabilities have been identified in the web-based management interface of EdgeConnect SD-WAN Orchestrator that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the EdgeConnect SD
nvd
CVE-2023-37428P3HIGHCVSS 7.2≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37428 [HIGH] CWE-22 CVE-2023-37428: A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
nvd
CVE-2025-37182P3HIGHCVSS 7.2≥ 9.2.0, ≤ 9.2.10≥ 9.3.0, ≤ 9.3.6+3 more2026-01-14
CVE-2025-37182 [HIGH] CWE-89 CVE-2025-37182: Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.
nvd
CVE-2025-37183P3HIGHCVSS 7.2≥ 9.2.0, ≤ 9.2.10≥ 9.3.0, ≤ 9.3.6+3 more2026-01-14
CVE-2025-37183 [HIGH] CWE-89 CVE-2025-37183: Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.
nvd
CVE-2025-37181P3HIGHCVSS 7.2≥ 9.2.0, ≤ 9.2.10≥ 9.3.0, ≤ 9.3.6+3 more2026-01-14
CVE-2025-37181 [HIGH] CWE-89 CVE-2025-37181: Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.
nvd
CVE-2024-41914P3CRITICALCVSS 9.0≥ 9.1.0, ≤ 9.1.9≥ 9.2.0, ≤ 9.2.9+2 more2024-07-24
CVE-2024-41914 [CRITICAL] CWE-79 CVE-2024-41914: A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of
nvd
CVE-2026-76686P3HIGHCVSS 7.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76686 [HIGH] CWE-400 CVE-2026-76686: A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gatew
A vulnerability exists in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an unauthenticated remote attacker to conduct a denial-of-service attack on the affected service.
nvd
CVE-2026-76697P3MEDIUMCVSS 6.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76697 [MEDIUM] CWE-200 CVE-2026-76697: A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways
A vulnerability in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE
nvd