High severity7.2NVD Advisory· Published Jul 24, 2024· Updated Jun 17, 2026
CVE-2024-22443
CVE-2024-22443
Description
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Affected products
4cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*range: >=9.1.0,<9.1.10
- (no CPE)range: EdgeConnect SD-WAN Orchestrator 9.4.x: Orchestrator 9.4.1 (all builds) and below
Patches
Vulnerability mechanics
References
1- support.hpe.com/hpesc/public/docDisplaynvdVendor Advisory
News mentions
0No linked articles in our index yet.