📦 Edgeconnect Sd Wan Orchestrator

by Arubanetworks

🔍 What is Edgeconnect Sd Wan Orchestrator?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-37184

CRITICAL CVSS 9.8 Jan 14, 2026

This vulnerability allows unauthenticated remote attackers to bypass multi-factor authentication requirements in an Orchestrator service, enabling them to create admin accounts without proper verifica...

CVE-2025-37182

HIGH CVSS 7.2 Jan 14, 2026

This vulnerability allows authenticated remote attackers to perform SQL injection attacks on EdgeConnect SD-WAN Orchestrator's web management interface. Successful exploitation could enable execution ...

CVE-2025-37183

HIGH CVSS 7.2 Jan 14, 2026

This SQL injection vulnerability in EdgeConnect SD-WAN Orchestrator's web management interface allows authenticated attackers to execute arbitrary SQL commands on the underlying database. Organization...

CVE-2025-37181

HIGH CVSS 7.2 Jan 14, 2026

This SQL injection vulnerability in EdgeConnect SD-WAN Orchestrator's web management interface allows authenticated attackers to execute arbitrary SQL commands on the underlying database. This could l...

CVE-2024-41914

HIGH CVSS 8.1 Jul 24, 2024

This stored XSS vulnerability in EdgeConnect SD-WAN Orchestrator's web management interface allows authenticated attackers to inject malicious scripts that execute in administrative users' browsers. A...

CVE-2024-22443

HIGH CVSS 7.2 Jul 24, 2024

This vulnerability allows authenticated remote attackers to conduct server-side prototype pollution attacks in EdgeConnect SD-WAN Orchestrator's web management interface. Successful exploitation could...

CVE-2023-37426

HIGH CVSS 7.4 Aug 22, 2023

EdgeConnect SD-WAN Orchestrator instances use shared static SSH host keys across all installations, allowing attackers to spoof legitimate Orchestrator hosts. This affects all EdgeConnect SD-WAN Orche...

CVE-2023-37428

HIGH CVSS 7.2 Aug 22, 2023

This vulnerability allows authenticated remote users to execute arbitrary commands as root on EdgeConnect SD-WAN Orchestrator systems through the web management interface. It affects organizations usi...

CVE-2023-37422

HIGH CVSS 8.1 Aug 22, 2023

This stored XSS vulnerability in EdgeConnect SD-WAN Orchestrator allows authenticated attackers to inject malicious scripts into the web interface. When an administrative user views the compromised pa...

CVE-2023-37424

HIGH CVSS 8.1 Aug 22, 2023

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on EdgeConnect SD-WAN Orchestrator systems if certain preconditions are met. It affects the web-based managemen...

CVE-2025-37185

MEDIUM CVSS 5.5 Jan 14, 2026

This stored XSS vulnerability in EdgeConnect SD-WAN Orchestrator's web interface allows authenticated attackers to inject malicious scripts that execute in administrative users' browsers. Attackers ca...

CVE-2024-41136

MEDIUM CVSS 6.8 Jul 24, 2024

An authenticated command injection vulnerability in HPE Aruba EdgeConnect SD-WAN gateways allows attackers with CLI access to execute arbitrary commands as privileged users on the underlying OS. This ...

CVE-2024-22444

MEDIUM CVSS 6.1 Jul 24, 2024

A reflected cross-site scripting (XSS) vulnerability in the EdgeConnect SD-WAN Orchestrator web management interface allows remote attackers to execute malicious JavaScript in victims' browsers. This ...