CVE-2023-37440
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Summary
CVE-2023-37440 is a newly disclosed vulnerability that affects the web-based management interface of EdgeConnect SD-WAN Orchestrator. An unauthenticated attacker can exploit this vulnerability through server-side request forgery (SSRF) attacks, potentially gaining unauthorized access to internal information. The vulnerability allows attackers to enumerate information about the EdgeConnect SD-WAN Orchestrator host, increasing the risk of sensitive data disclosure. This issue poses a significant threat to organizations using this SD-WAN solution and emphasizes the importance of timely patching and secure configuration management.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Aruba Networks