Description
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41328 | A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. |
References
History
Thu, 03 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hpe
Hpe edgeconnect Sd-wan Orchestrator |
|
| CPEs | cpe:2.3:a:hpe:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hpe
Hpe edgeconnect Sd-wan Orchestrator |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: hpe
Published:
Updated: 2024-10-03T14:48:07.190Z
Reserved: 2023-07-05T17:36:47.997Z
Link: CVE-2023-37428
Updated: 2024-08-02T17:16:29.573Z
Status : Modified
Published: 2023-08-22T19:16:37.423
Modified: 2024-11-21T08:11:41.380
Link: CVE-2023-37428
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD