VYPR
Low severity3.8NVD Advisory· Published Dec 12, 2022· Updated Jun 17, 2026

CVE-2022-37911

CVE-2022-37911

Description

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

Affected products

4
  • cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
    Range: >=8.7.0.0-2.3.0.0,<8.7.0.0-2.3.0.6
  • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*range: >=6.5.4.0,<6.5.4.22
    • (no CPE)
  • Hewlett Packard Enterprise/Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Centralv5
    Range: ArubaOS 6.5.4.x: 6.5.4.23 and above; ArubaOS 8.6.x: 8.6.0.18 and above; ArubaOS 8.7.x: 8.7.1.10 and above; ArubaOS 8.10.x: 8.10.0.0 and above; ArubaOS 10.3.x: 10.3.0.1 and above; SD-WAN-2.3.0.x: 8.7.0.0-2.3.0.7 and above

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.