CVE-2023-37433
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Aug 22, 2023
Updated: Aug 29, 2023
CWE ID 89
Summary
CVE-2023-37433 refers to multiple SQL injection vulnerabilities present in the web-based management interface of EdgeConnect SD-WAN Orchestrator. These flaws enable authenticated remote attackers to manipulate data in the underlying database, potentially causing the exposure and corruption of sensitive data managed by the EdgeConnect SD-WAN Orchestrator host. Successful exploitation could grant an attacker unauthorized access to valuable information.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Aruba Networks