cbcvebase.

Arubanetworks Edgeconnect Sd-Wan Orchestrator vulnerabilities

67 known vulnerabilities affecting arubanetworks/edgeconnect_sd-wan_orchestrator.

Total CVEs
67
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH33MEDIUM26

Vulnerabilities

Page 4 of 4
CVE-2024-22444P4MEDIUMCVSS 6.1≥ 9.1.0, ≤ 9.1.9≥ 9.2.0, ≤ 9.2.9+2 more2024-07-24
CVE-2024-22444 [MEDIUM] CWE-79 CVE-2024-22444: A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could a A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface
nvd
CVE-2023-37422P4MEDIUMCVSS 5.4≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37422 [MEDIUM] CWE-79 CVE-2023-37422: Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of th
nvd
CVE-2023-37423P4MEDIUMCVSS 5.4≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37423 [MEDIUM] CWE-79 CVE-2023-37423: Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of th
nvd
CVE-2023-37421P4MEDIUMCVSS 5.4≥ 9.0.0, ≤ 9.0.5≥ 9.1.0, ≤ 9.1.7+2 more2023-08-22
CVE-2023-37421 [MEDIUM] CWE-79 CVE-2023-37421: Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of th
nvd
CVE-2026-76702P4MEDIUMCVSS 5.8≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76702 [MEDIUM] CWE-400 CVE-2026-76702: A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an A vulnerability in the operating system of HPE Networking EdgeConnect SD-WAN Gateways could allow an authenticated local attacker to cause a denial-of-service. Successful exploitation could allow an attacker to disrupt system operations, potentially resulting in an unstable system state.
nvd
CVE-2026-76707P4MEDIUMCVSS 4.3≥ 9.4.0, < 9.4.11≥ 9.5.0, < 9.5.9+2 more2026-09-15
CVE-2026-76707 [MEDIUM] CWE-200 CVE-2026-76707: A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacen A vulnerability in HPE Networking EdgeConnect SD-WAN Gateways could allow an unauthenticated adjacent attacker to view some system memory contents. Successful exploitation could allow an attacker to gain insight into internal services and workflows, increasing the risk of unauthorized access and elevated privileges when combined with other vulnerabi
nvd
CVE-2025-37185P4MEDIUMCVSS 4.8≥ 9.2.0, ≤ 9.2.10≥ 9.3.0, ≤ 9.3.6+3 more2026-01-14
CVE-2025-37185 [MEDIUM] CWE-79 CVE-2025-37185: Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attacks against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of t
nvd
Arubanetworks Edgeconnect Sd-Wan Orchestrator vulnerabilities | cvebase