CVE-2024-22443: Arubanetworks Edgeconnect SD-WAN Orchestrator

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Affected products

  • Arubanetworks Edgeconnect SD-WAN Orchestrator: from 9.1.0, before 9.1.10 (fixed in 9.1.10); from 9.2.0, before 9.2.10 (fixed in 9.2.10); from 9.3.0, before 9.3.3 (fixed in 9.3.3); from 9.4.0, before 9.4.2 (fixed in 9.4.2)

Published 2024-07-24. Last modified 2026-06-17.