High severity7.2NVD Advisory· Published Dec 12, 2022· Updated Jun 17, 2026
CVE-2022-37903
CVE-2022-37903
Description
A vulnerability exists that allows an authenticated attacker to overwrite an arbitrary file with attacker-controlled content via the web interface. Successful exploitation of this vulnerability could lead to full compromise the underlying host operating system.
Affected products
4- Hewlett Packard Enterprise/Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Centralv5Range: ArubaOS 6.5.4.x: 6.5.4.23 and above; ArubaOS 8.6.x: 8.6.0.18 and above; ArubaOS 8.7.x: 8.7.1.10 and above; ArubaOS 8.10.x: 8.10.0.0 and above; ArubaOS 10.3.x: 10.3.0.1 and above; SD-WAN-2.3.0.x: 8.7.0.0-2.3.0.7 and above
- cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*Range: >=8.7.0.0-2.3.0.0,<8.7.0.0-2.3.0.7
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*range: >=6.5.4.0,<6.5.4.23
- cpe:2.3:o:arubanetworks:arubaos:10.3.0.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txtnvdVendor Advisory
News mentions
0No linked articles in our index yet.