CVE-2022-37908
בינונית 6.5
תיאור (מקור, אנגלית)
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N - CWE
- CWE-494
מוצרים מושפעים
arubanetworks: sd-wan; arubanetworks: arubaos; arubanetworks: 7005; arubanetworks: 7008; arubanetworks: 7010; arubanetworks: 7024; arubanetworks: 7030; arubanetworks: 7205; arubanetworks: 7210; arubanetworks: 7220; arubanetworks: 7240xm; arubanetworks: 7280
קישורים
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt Vendor Advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt Vendor Advisory