Arubanetworks
Arubanetworks Aruba Edgeconnect Enterprise Orchestrator: vulnerabilidades y CVE
Arubanetworks Aruba Edgeconnect Enterprise Orchestrator tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-44535 | Alta (8.8) | 0.90% | — | 5 ene 2023 | A vulnerability in the Aruba EdgeConnect Enterprise Orchestrator web-based management interface allows remote low-privileged authenticated users to escalate their privileges to those of an administrative user. A… |
| CVE-2022-44534 | Alta (7.2) | 1.1% | — | 5 ene 2023 | A vulnerability in the Aruba EdgeConnect Enterprise Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an… |
| CVE-2022-43529 | Media (5.4) | 0.43% | — | 5 ene 2023 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event. Successful… |
| CVE-2022-43528 | Media (6.5) | 0.37% | — | 5 ene 2023 | Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a… |
| CVE-2022-43527 | Media (6.1) | 0.46% | — | 5 ene 2023 | Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of… |
| CVE-2022-43526 | Media (6.1) | 0.46% | — | 5 ene 2023 | Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of… |
| CVE-2022-43525 | Media (6.1) | 0.46% | — | 5 ene 2023 | Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of… |
| CVE-2022-43524 | Media (5.4) | 0.51% | — | 5 ene 2023 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an… |
| CVE-2022-43523 | Alta (8.8) | 0.95% | — | 5 ene 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect… |
| CVE-2022-43522 | Alta (8.8) | 0.95% | — | 5 ene 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect… |
| CVE-2022-43521 | Alta (8.8) | 0.95% | — | 5 ene 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect… |
| CVE-2022-43520 | Alta (8.8) | 0.95% | — | 5 ene 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect… |
| CVE-2022-43519 | Alta (8.8) | 0.95% | — | 5 ene 2023 | Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an authenticated remote attacker to conduct SQL injection attacks against the Aruba EdgeConnect… |
| CVE-2022-37915 | Crítica (9.8) | 1.7% | — | 28 oct 2022 | A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation… |
| CVE-2022-37914 | Crítica (9.8) | 1.5% | — | 28 oct 2022 | Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these… |
| CVE-2022-37913 | Crítica (9.8) | 1.5% | — | 28 oct 2022 | Vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an unauthenticated remote attacker to bypass authentication. Successful exploitation of these… |