CVE-2024-33519: Arubanetworks Edgeconnect SD-WAN Orchestrator
High severity, CVSS 7.2. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
Affected products
- Arubanetworks Edgeconnect SD-WAN Orchestrator: from 9.3.0, up to and including 9.3.3.0; from 9.2.0, up to and including 9.2.9.0; from 9.1.0, up to and including 9.1.11.0; from 9.0.0, before 9.1.0 (fixed in 9.1.0); from 8.0.0, before 8.0.1 (fixed in 8.0.1)
- Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN
Published 2024-07-24. Last modified 2026-06-17.