CVE-2024-41135: Arubanetworks Edgeconnect SD-WAN Orchestrator

High severity, CVSS 7.2. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise

Affected products

  • Arubanetworks Edgeconnect SD-WAN Orchestrator: from 8.0.0, before 8.0.1 (fixed in 8.0.1); from 9.3.0, up to and including 9.3.3.0; from 9.2.0, up to and including 9.2.9.0; from 9.1.0, up to and including 9.1.11.0; from 9.0.0, before 9.1.0 (fixed in 9.1.0)
  • Hewlett Packard Enterprise HPE HPE Aruba Networking Edgeconnect SD-WAN

Published 2024-07-24. Last modified 2026-06-17.