VendorsAruba Networksedgeconnect_enterpriseall versions
Vulnerabilities

Aruba Networks EdgeConnect Enterprise

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2022-43542
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
8.8EPSS 0.012
CVE-2023-30506
Authenticated Remote Code Execution in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
8.8EPSS 0.011
CVE-2023-30502
Authenticated Remote Code Execution in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
8.8EPSS 0.011
CVE-2023-30505
Authenticated Remote Code Execution in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
8.8EPSS 0.010
CVE-2023-30504
Authenticated Remote Code Execution in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
8.8EPSS 0.010
CVE-2023-30503
Authenticated Remote Code Execution in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
8.8EPSS 0.010
CVE-2023-30501
Authenticated Remote Code Execution in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
8.8EPSS 0.010
CVE-2020-12148
OS Command Injection - nslookup API
Published 2020-12-11 · Modified
8.5EPSS 0.021
CVE-2020-12149
OS Command Injection - Management File Upload
Published 2020-12-11 · Modified
8.5EPSS 0.013
CVE-2022-37919
A vulnerability exists in the API of Aruba EdgeConnect Enterprise. An unauthenticated attacker can exploit this condition via the web-based management interface to create a denial-of-service condition which prevents the appliance from properly responding to API requests in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below;
Published 2022-11-30 · Modified
7.5EPSS 0.007
CVE-2022-43541
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
7.2EPSS 0.016
CVE-2022-37924
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
7.2EPSS 0.016
CVE-2022-37923
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
7.2EPSS 0.014
CVE-2022-37922
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
7.2EPSS 0.014
CVE-2022-37921
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
7.2EPSS 0.014
CVE-2022-37920
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
7.2EPSS 0.014
CVE-2022-44533
A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
7.2EPSS 0.013
CVE-2022-43518
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
6.5EPSS 0.007
CVE-2022-44532
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
6.5EPSS 0.007
CVE-2023-30507
Authenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
6.5EPSS 0.006
CVE-2023-30508
Authenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
6.5EPSS 0.006
CVE-2023-30509
Authenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line Interface
Published 2023-05-16 · Modified
6.5EPSS 0.006
CVE-2022-37925
A vulnerability within the web-based management interface of Aruba EdgeConnect Enterprise could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
6.1EPSS 0.005
CVE-2022-37926
A vulnerability within the web-based management interface of EdgeConnect Enterprise could allow a remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface by uploading a specially crafted file. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Published 2022-11-30 · Modified
5.5EPSS 0.005
CVE-2023-30510
Authenticated Server-side Request Forgery in Aruba EdgeConnect Enterprise Web Management Interface
Published 2023-05-16 · Modified
4.3EPSS 0.006