An authenticated command injection vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateways Command Line Interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
References
Link | Resource |
---|---|
https://csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04673.txt | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-07-24 21:15
Updated : 2024-07-26 13:22
NVD link : CVE-2024-41136
Mitre link : CVE-2024-41136
CVE.ORG link : CVE-2024-41136
JSON object : View
Products Affected
arubanetworks
- edgeconnect_sd-wan_orchestrator
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')