VendorsAruba Networksedgeconnect_sd-wan_orchestratorany version
Vulnerabilities

Aruba Networks EdgeConnect SD-WAN Orchestrator any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2025-37184
Unauthenticated Bypass Allows Multi-Factor Authentication Circumvention
Published 2026-01-14 · Modified
9.8EPSS 0.007
CVE-2024-41914
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Published 2024-07-24 · Modified
9.0EPSS 0.005
CVE-2024-41136
Authenticated Command Injection in HPE Aruba Networking EdgeConnect SD-WAN Command Line Interface
Published 2024-07-24 · Modified
8.8EPSS 0.009
CVE-2024-22443
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Published 2024-07-24 · Modified
8.8EPSS 0.008
CVE-2023-37434
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
8.1EPSS 0.010
CVE-2023-37424
Unauthenticated Remote Code Execution in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Published 2023-08-22 · Modified
8.1EPSS 0.009
CVE-2023-37432
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
8.1EPSS 0.008
CVE-2023-37433
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
8.1EPSS 0.008
CVE-2023-37431
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
8.1EPSS 0.008
CVE-2023-37430
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
8.1EPSS 0.008
CVE-2023-37429
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
8.1EPSS 0.008
CVE-2023-37421
Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
Published 2023-08-22 · Modified
8.1EPSS 0.005
CVE-2023-37423
Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
Published 2023-08-22 · Modified
8.1EPSS 0.005
CVE-2023-37422
Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
Published 2023-08-22 · Modified
8.1EPSS 0.005
CVE-2023-37425
Unauthenticated Stored Cross-Site Scripting Vulnerability (XSS) in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Published 2023-08-22 · Modified
8.0EPSS 0.005
CVE-2023-37426
Shared SSH Static Host Keys in EdgeConnect SD-WAN Orchestrator
Published 2023-08-22 · Modified
7.5EPSS 0.005
CVE-2023-37427
Authenticated Remote Code Execution in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Published 2023-08-22 · Modified
7.2EPSS 0.013
CVE-2023-37428
Authenticated Remote Code Execution via Path Traversal in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Published 2023-08-22 · Modified
7.2EPSS 0.011
CVE-2025-37183
Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Published 2026-01-14 · Analyzed
7.2EPSS 0.005
CVE-2025-37182
Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Published 2026-01-14 · Analyzed
7.2EPSS 0.005
CVE-2025-37181
Authenticated SQL Injection in EdgeConnect SD-WAN Orchestrator Web-Based Management Interface
Published 2026-01-14 · Analyzed
7.2EPSS 0.005
CVE-2023-37435
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
6.5EPSS 0.008
CVE-2023-37438
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
6.5EPSS 0.008
CVE-2023-37437
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
6.5EPSS 0.008
CVE-2023-37436
Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based Management Interface
Published 2023-08-22 · Modified
6.5EPSS 0.008
CVE-2023-37439
Reflected Cross Site Scripting in EdgeConnect SD-WAN Orchestrator Web Management Interface
Published 2023-08-22 · Modified
6.1EPSS 0.005
CVE-2024-22444
A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.
Published 2024-07-24 · Modified
6.1EPSS 0.003
CVE-2023-37440
Authenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure
Published 2023-08-22 · Modified
5.5EPSS 0.006
CVE-2025-37185
Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orchestrator Web Administration Interface
Published 2026-01-14 · Analyzed
5.5EPSS 0.003