Aruba Alert
2041Warning Date
Severity Level
Warning Number
Target Sector
22 August, 2023
● High
2023-5743
All
Description:
Aruba has released security updates to address multiple vulnerabilities in the following products:
- EdgeConnect SD-WAN Orchestrator (self-hosted, on-premises)
- EdgeConnect SD-WAN Orchestrator (self-hosted, public cloud IaaS)
- EdgeConnect SD-WAN Orchestrator-as-a-Service
- EdgeConnect SD-WAN Orchestrator-SP Tenant Orchestrators
- EdgeConnect SD-WAN Orchestrator Global Enterprise Tenant Orchestrators.
- Orchestrator 9.3.x: Orchestrator 9.3.0 (all builds) and below
- Orchestrator 9.2.x: Orchestrator 9.2.5 (all builds) and below
- Orchestrator 9.1.x: Orchestrator 9.1.7 (all builds) and below
- Orchestrator 9.0.x: All versions
- Any older branches of Orchestrator not specifically mentioned
Threats:
The attacker could exploit these vulnerabilities by doing the following:
- Remote Code Execution
- Stored XSS
- Shared SSH Static Host Keys
Best practice and Recommendations:
The CERT team encourages users to review Aruba security advisory and apply the necessary updates:
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-012.txt