VYPR
Medium severity6.8NVD Advisory· Published Jul 24, 2024· Updated Jun 17, 2026

CVE-2024-41136

CVE-2024-41136

Description

An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

Affected products

6
  • cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*range: >=9.1.0,<=9.1.11
    • cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:8.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.3.0:*:*:*:*:*:*:*
  • Hewlett Packard Enterprise (HPE)/HPE Aruba Networking EdgeConnect SD-WANv5
    Range: ECOS 9.3.x.x: 9.3.3.0 and below

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.