← Back

CVE-2022-37908

nvd nist
Published: Dec 12, 2022Modified: May 2, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.

Affected (5)

2 products
Arubaos
Sd Wan
Configuration A
5 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Arubanetworks
From 6.5.4.0 to 6.5.4.22
From 8.4.0.0 to 8.6.0.17
From 8.7.0.0 to 8.7.1.9
From 8.8.0.0 to 10.3.0.1
From 8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.6
Running on/withPlatform Versions
Arubanetworks
7005
All versions
Arubanetworks
7008
All versions
Arubanetworks
7010
All versions
Arubanetworks
7024
All versions
Arubanetworks
7030
All versions
Arubanetworks
7205
All versions
Arubanetworks
7210
All versions
Arubanetworks
7220
All versions
Arubanetworks
7240xm
All versions
Arubanetworks
7280
All versions

References (2)

Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.