CVE-2023-37427: Arubanetworks Edgeconnect SD-WAN Orchestrator
High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
Affected products
- Arubanetworks Edgeconnect SD-WAN Orchestrator: from 9.0.0, up to and including 9.0.5; from 9.1.0, up to and including 9.1.7; from 9.2.0, up to and including 9.2.5; version 9.3.0 only
Published 2023-08-22. Last modified 2026-06-17.