NA

CVE-2023-37426

Published: 22/08/2023 Updated: 30/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an malicious user to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

arubanetworks edgeconnect sd-wan orchestrator 9.3.0

arubanetworks edgeconnect sd-wan orchestrator