Medium severity6.1NVD Advisory· Published Jul 24, 2024· Updated Jun 17, 2026
CVE-2024-22444
CVE-2024-22444
Description
A vulnerability within the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victims browser in the context of the affected interface.
Affected products
3cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*range: >=9.1.0,<=9.1.9
- (no CPE)range: EdgeConnect SD-WAN Orchestrator 9.4.x: Orchestrator 9.4.1 (all builds) and below
Patches
Vulnerability mechanics
References
1- support.hpe.com/hpesc/public/docDisplaynvdVendor Advisory
News mentions
0No linked articles in our index yet.