CVE-2022-37907

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/12/2022
Last modified:
02/05/2025

Description

A vulnerability exists in the ArubaOS bootloader on 7xxx series controllers which can result in a denial of service (DoS) condition on an impacted system. A successful attacker can cause a system hang which can only be resolved via a power cycle of the impacted controller. <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:arubanetworks:sd-wan:*:*:*:*:*:*:*:* 8.7.0.0-2.3.0.0 (including) 8.7.0.0-2.3.0.6 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 6.5.4.0 (including) 6.5.4.22 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 8.4.0.0 (including) 8.6.0.17 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 8.7.0.0 (including) 8.7.1.9 (excluding)
cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* 8.8.0.0 (including) 10.3.0.1 (excluding)
cpe:2.3:h:arubanetworks:7005:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7008:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7010:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7024:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7030:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7205:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7210:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7220:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7240xm:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:7280:-:*:*:*:*:*:*:*