Arubanetworks Edgeconnect Sd-Wan Orchestrator vulnerabilities
67 known vulnerabilities affecting arubanetworks/edgeconnect_sd-wan_orchestrator.
Total CVEs
67
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH33MEDIUM26
Vulnerabilities
Page 3 of 4
CVE-2026-76694P3MEDIUMCVSS 6.6≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76694 [MEDIUM] CWE-269 CVE-2026-76694: A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConn
A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.
nvd
CVE-2023-37426P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37426 [HIGH] CWE-798 CVE-2023-37426: EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator
host.
nvd
CVE-2026-76695P3MEDIUMCVSS 6.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76695 [MEDIUM] CWE-120 CVE-2026-76695: Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConne
Buffer overflow vulnerabilities exist in the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated remote attacker to send specially crafted packets to the affected service. Successful exploitation could allow an attacker to affect the integrity and availability of the affected service.
nvd
CVE-2026-76693P3HIGHCVSS 7.0≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76693 [HIGH] CWE-400 CVE-2026-76693: A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service against certain services running on impacted Gateways.
nvd
CVE-2026-76705P3MEDIUMCVSS 5.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76705 [MEDIUM] CWE-120 CVE-2026-76705: A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gate
A buffer overflow vulnerability exists in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with Admin privilege to execute arbitrary commands on the underlying operating system.
nvd
CVE-2023-37436P3MEDIUMCVSS 6.5fixed in 9.3.12023-08-22
CVE-2023-37436 [MEDIUM] CWE-89 CVE-2023-37436: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database pote
nvd
CVE-2023-37435P3MEDIUMCVSS 6.5fixed in 9.3.12023-08-22
CVE-2023-37435 [MEDIUM] CWE-89 CVE-2023-37435: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database pote
nvd
CVE-2023-37438P3MEDIUMCVSS 6.5fixed in 9.3.12023-08-22
CVE-2023-37438 [MEDIUM] CWE-89 CVE-2023-37438: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database pote
nvd
CVE-2023-37437P3MEDIUMCVSS 6.5fixed in 9.3.12023-08-22
CVE-2023-37437 [MEDIUM] CWE-89 CVE-2023-37437: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database pote
nvd
CVE-2026-76701P3MEDIUMCVSS 5.9≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76701 [MEDIUM] CWE-306 CVE-2026-76701: A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an una
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to access sensitive information. Successful exploitation could allow an attacker to retrieve information which could be used to potentially gain further access to network services supported by HPE Networking EdgeConnect SD
nvd
CVE-2026-76699P4MEDIUMCVSS 6.4≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76699 [MEDIUM] CWE-120 CVE-2026-76699: A buffer overflow vulnerability exists in a system service within the underlying operating system of
A buffer overflow vulnerability exists in a system service within the underlying operating system of HPE Networking EdgeConnect SD-WAN Gateways that could allow an unauthenticated adjacent attacker to cause a denial-of-service. Successful exploitation could allow an attacker to crash the impacted service and temporarily disrupting network operations
nvd
CVE-2026-76700P4MEDIUMCVSS 5.9≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76700 [MEDIUM] CWE-400 CVE-2026-76700: Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote
Vulnerabilities in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated remote attacker to cause a denial-of-service. Successful exploitation could allow an attacker to interrupt the normal operation of the affected service.
nvd
CVE-2023-37439P4MEDIUMCVSS 6.1fixed in 9.1.8≥ 9.2.0, < 9.2.6+1 more2023-08-22
CVE-2023-37439 [MEDIUM] CWE-79 CVE-2023-37439: Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator co
Multiple vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the EdgeConnect SD-WAN Orchestrator instance. An attacker could exploit these vulnerabilities to
obtain and modify sensitive information in the underlying database pote
nvd
CVE-2026-76703P4MEDIUMCVSS 5.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76703 [MEDIUM] CWE-120 CVE-2026-76703: A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeC
A buffer overflow vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN Gateways that could allow an authenticated attacker with administrative access to cause a denial of service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
nvd
CVE-2026-76704P4MEDIUMCVSS 5.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76704 [MEDIUM] CWE-79 CVE-2026-76704: A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could a
A vulnerability in the web-based management interface of the EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to execute arbitrary script code in a victim's browser in the context of the affected interface. Successful exploitation could allow an attacker to access sensitive information, potentially affecting the confidenti
nvd
CVE-2026-76692P4HIGHCVSS 7.1≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76692 [HIGH] CWE-200 CVE-2026-76692: A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacen
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to obtain limited information from memory and disrupt the normal operation of the affected service. Successful exploitation could result in a denial of service (system crash) or the disclosure of uninitialized stack memory.
nvd
CVE-2026-76706P4MEDIUMCVSS 5.3≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76706 [MEDIUM] CWE-200 CVE-2026-76706: A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an
A vulnerability in the API endpoint of HPE Networking EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to obtain sensitive information. Successful exploitation could result in the disclosure of security-relevant configuration details and security feature status, which could be used to facilitate further attacks.
nvd
CVE-2026-76696P4MEDIUMCVSS 6.5≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76696 [MEDIUM] CWE-400 CVE-2026-76696: A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacen
A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to conduct a denial of service attack. Successful exploitation could allow an attacker to crash the system, preventing it from rebooting without manual intervention and disrupting network operations.
nvd
CVE-2023-37440P4MEDIUMCVSS 5.3fixed in 9.3.12023-08-22
CVE-2023-37440 [MEDIUM] CWE-918 CVE-2023-37440: A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a server-side request forgery (SSRF) attack. A successful exploit allows an attacker to enumerate information about the internal
structure of the EdgeConnect SD-WAN Orchestrator host leading to potential
nvd
CVE-2023-37425P4MEDIUMCVSS 6.1≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37425 [MEDIUM] CWE-79 CVE-2023-37425: A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of
nvd