CVE-2022-43518
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files in Aruba EdgeConnect Enterprise Software version(s): ECOS 9.2.1.0 and below; ECOS 9.1.3.0 and below; ECOS 9.0.7.0 and below; ECOS 8.3.7.1 and below.
Existe una vulnerabilidad de path traversal autenticada en la interfaz web de Aruba EdgeConnect Enterprise. La explotación exitosa de esta vulnerabilidad da como resultado la capacidad de leer archivos arbitrarios en el sistema operativo subyacente, incluidos archivos confidenciales del sistema en las versiones del software Aruba EdgeConnect Enterprise: ECOS 9.2.1.0 y anteriores; ECOS 9.1.3.0 y anteriores; ECOS 9.0.7.0 y anteriores; ECOS 8.3.7.1 y anteriores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-20 CVE Reserved
- 2022-11-30 CVE Published
- 2024-06-22 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-018.txt | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Edgeconnect Enterprise Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" | >= 8.3.1.0 <= 8.3.7.1 Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" and version " >= 8.3.1.0 <= 8.3.7.1" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Edgeconnect Enterprise Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" | >= 9.0.0.0 <= 9.0.7.0 Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" and version " >= 9.0.0.0 <= 9.0.7.0" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Edgeconnect Enterprise Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" | >= 9.1.0.0 <= 9.1.3.0 Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" and version " >= 9.1.0.0 <= 9.1.3.0" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Edgeconnect Enterprise Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" | >= 9.2.0.0 <= 9.2.1.0 Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" and version " >= 9.2.0.0 <= 9.2.1.0" | - |
Affected
|