Unrated severityNVD Advisory· Published Jul 24, 2024· Updated Aug 12, 2024
CVE-2024-41914
CVE-2024-41914
Description
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected products
2- Hewlett Packard Enterprise/HPE Aruba Networking EdgeConnect SD-WAN Orchestratorv5Range: EdgeConnect SD-WAN Orchestrator 9.4.x: Orchestrator 9.4.1 (all builds) and below
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.