EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were found to have shared static SSH host keys for all installations. This vulnerability could allow an attacker to spoof the SSH host signature and thereby masquerade as a legitimate Orchestrator host.
History

Thu, 03 Oct 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Hpe
Hpe edgeconnect Sd-wan Orchestrator
CPEs cpe:2.3:a:hpe:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
Vendors & Products Hpe
Hpe edgeconnect Sd-wan Orchestrator
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published: 2023-08-22T18:02:22.824Z

Updated: 2024-10-03T15:04:38.699Z

Reserved: 2023-07-05T17:36:47.997Z

Link: CVE-2023-37426

cve-icon Vulnrichment

Updated: 2024-08-02T17:16:29.531Z

cve-icon NVD

Status : Modified

Published: 2023-08-22T19:16:37.210

Modified: 2024-11-21T08:11:41.097

Link: CVE-2023-37426

cve-icon Redhat

No data.