CVE-2022-37904

Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:arubaos:10.3.0.0:*:*:*:*:*:*:*
OR cpe:2.3:h:arubanetworks:7005:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7008:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7010:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7024:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7030:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7205:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7210:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7220:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7240xm:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7280:-:*:*:*:*:*:*:*

History

02 May 2025, 19:15

Type Values Removed Values Added
CWE CWE-123

21 Nov 2024, 07:15

Type Values Removed Values Added
Summary
  • (es) Existen vulnerabilidades en ArubaOS que se ejecutan en controladores de la serie 7xxx que permiten a un atacante ejecutar código arbitrario durante la secuencia de inicio. La explotación exitosa podría permitir a un atacante lograr una modificación permanente del sistema operativo subyacente.
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 6.6
References () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt - Vendor Advisory () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt - Vendor Advisory

Information

Published : 2022-12-12 13:15

Updated : 2025-05-02 19:15


NVD link : CVE-2022-37904

Mitre link : CVE-2022-37904

CVE.ORG link : CVE-2022-37904


JSON object : View

Products Affected

arubanetworks

  • arubaos
  • 7010
  • 7005
  • 7030
  • 7210
  • sd-wan
  • 7280
  • 7008
  • 7205
  • 7220
  • 7240xm
  • 7024
CWE
NVD-CWE-noinfo CWE-123

Write-what-where Condition