Description
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.

Published: 2022-11-30
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-46516 An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
History

Thu, 24 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Edgeconnect Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-04-24T14:45:29.312Z

Reserved: 2022-10-20T12:58:24.594Z

Link: CVE-2022-43518

cve-icon Vulnrichment

Updated: 2024-08-03T13:32:59.617Z

cve-icon NVD

Status : Modified

Published: 2022-12-12T13:15:14.857

Modified: 2025-04-24T15:15:51.633

Link: CVE-2022-43518

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses