Description
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator
host.
Published: 2023-08-22
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-41326 EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.
History

Thu, 03 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe edgeconnect Sd-wan Orchestrator
CPEs cpe:2.3:a:hpe:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
Vendors & Products Hpe
Hpe edgeconnect Sd-wan Orchestrator
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Arubanetworks Edgeconnect Sd-wan Orchestrator
Hpe Edgeconnect Sd-wan Orchestrator
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-10-03T15:04:38.699Z

Reserved: 2023-07-05T17:36:47.997Z

Link: CVE-2023-37426

cve-icon Vulnrichment

Updated: 2024-08-02T17:16:29.531Z

cve-icon NVD

Status : Modified

Published: 2023-08-22T19:16:37.210

Modified: 2024-11-21T08:11:41.097

Link: CVE-2023-37426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses