A vulnerability in the Aruba EdgeConnect Enterprise Orchestrator web-based management interface allows remote low-privileged authenticated users to escalate their privileges to those of an administrative user
Published Jan 3, 2023
8.8
HIGHCVSS 3.1
EPSS 0.90%
Description
A vulnerability in the Aruba EdgeConnect Enterprise Orchestrator web-based management interface allows remote low-privileged authenticated users to escalate their privileges to those of an administrative user. A successful exploit could allow an attacker to achieve administrative privilege on the web-management interface leading to complete system compromise in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.
Affected products
- Vendor Hewlett Packard Enterprise (HPE) Product Aruba EdgeConnect Enterprise Orchestration Software Defaultunaffected
- Version Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | Aruba EdgeConnect Enterprise Orchestration Software | unaffected |
|
Configuration 1
- ≤ 8.10.23.40015
- ≥ 9.0.0 · ≤ 9.0.7.40110
- ≥ 9.1.0 · ≤ 9.1.4.40436
- ≥ 9.2.0 · ≤ 9.2.1.40179
Configuration 2
- ≤ 8.10.23.40015
- ≥ 9.0.0 · ≤ 9.0.7.40110
- ≥ 9.1.0 · ≤ 9.1.4.40436
- ≥ 9.2.0 · ≤ 9.2.1.40179
Configuration 3
- ≤ 8.10.23.40015
- ≥ 9.0.0 · ≤ 9.0.7.40110
- ≥ 9.1.0 · ≤ 9.1.4.40436
- ≥ 9.2.0 · ≤ 9.2.1.40179
Configuration 4
- ≤ 8.10.23.40015
- ≥ 9.0.0 · ≤ 9.0.7.40110
- ≥ 9.1.0 · ≤ 9.1.4.40436
- ≥ 9.2.0 · ≤ 9.2.1.40179
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Apr 10, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2023–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.90% (0.00897) | 58.20th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.90% (0.00897) | 54.73th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.60% (0.00597) | 67.50th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.26% (0.00258) | 66.05th | v3 (v2023.03.01) |
| Jan 10, 2024 | 0.19% (0.00190) | 56.59th | v3 (v2023.03.01) |
| Dec 4, 2023 | 0.12% (0.00121) | 46.02th | v3 (v2023.03.01) |
| Nov 15, 2023 | 0.10% (0.00104) | 42.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.10% (0.00103) | 40.46th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.05% (0.01055) | 52.13th | v2 (v2022.01.01) |
| Jan 4, 2023 | 1.05% (0.01055) | 51.18th | v2 (v2022.01.01) |
No CWE recorded.
References (1)
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-021.txt MitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-021.txt | MitigationVendor Advisory |
Change history (0)
No recorded changes yet.