VYPR
High severity7.2NVD Advisory· Published Dec 12, 2022· Updated Jun 17, 2026

CVE-2022-37898

CVE-2022-37898

Description

Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

Affected products

5
  • cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
    Range: >=8.7.0.0-2.3.0.0,<8.7.0.0-2.3.0.7
  • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*range: >=6.5.4.0,<6.5.4.23
    • cpe:2.3:o:arubanetworks:arubaos:10.3.0.0:*:*:*:*:*:*:*
    • (no CPE)
  • Hewlett Packard Enterprise/Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Centralv5
    Range: ArubaOS 6.5.4.x: 6.5.4.23 and above; ArubaOS 8.6.x: 8.6.0.18 and above; ArubaOS 8.7.x: 8.7.1.10 and above; ArubaOS 8.10.x: 8.10.0.0 and above; ArubaOS 10.3.x: 10.3.0.1 and above; SD-WAN-2.3.0.x: 8.7.0.0-2.3.0.7 and above

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.