HPE Aruba Networking EdgeConnect SD-WAN Vulnerabilities & Security Advisories
17 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as EdgeConnect SD-WAN, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 9 high, 7 medium.
Android app · Google Play
Monitor Aruba CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
HPE Aruba Networking Security Advisories (PSIRT) via NVD
Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.
Latest Aruba EdgeConnect SD-WAN advisories
High [CVE-2025-37183] Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could
Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.
High [CVE-2025-37127] vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could
A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access and control over the affected systems.
High [CVE-2025-37126] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.
High [CVE-2025-37125] EdgeConnect: broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS).
A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly
High [CVE-2025-37123] vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could
A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.
High [CVE-2024-41135] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise
High [CVE-2024-33519] vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could
A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.
High [CVE-2024-41914] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
High [CVE-2024-22443] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.