VYPR
High severity7.2NVD Advisory· Published Dec 12, 2022· Updated Jun 17, 2026

CVE-2022-37903

CVE-2022-37903

Description

A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.

Affected products

4
  • Hewlett Packard Enterprise/Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Centralv5
    Range: ArubaOS 6.5.4.x: 6.5.4.23 and above; ArubaOS 8.6.x: 8.6.0.18 and above; ArubaOS 8.7.x: 8.7.1.10 and above; ArubaOS 8.10.x: 8.10.0.0 and above; ArubaOS 10.3.x: 10.3.0.1 and above; SD-WAN-2.3.0.x: 8.7.0.0-2.3.0.7 and above
  • cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
    Range: >=8.7.0.0-2.3.0.0,<8.7.0.0-2.3.0.7
  • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*range: >=6.5.4.0,<6.5.4.23
    • cpe:2.3:o:arubanetworks:arubaos:10.3.0.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.