Skip to content
VulniPulse

HPE Aruba Networking EdgeConnect SD-WAN Vulnerabilities & Security Advisories

17 advisories tracked · HPE Aruba Networking Security Advisories (PSIRT) via NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published HPE Aruba Networking advisory that VulniPulse classified as EdgeConnect SD-WAN, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 9 high, 7 medium.

Android app · Google Play

Monitor Aruba CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

HPE Aruba Networking Security Advisories (PSIRT) via NVD

Aruba's PSIRT bulletin portal (arubanetworks.com) is a JavaScript app with no stable public feed, so VulniPulse ingests Aruba's CVEs from NVD. Aruba publishes under the shared HPE CNA (security-alert@hpe.com), which also covers non-networking HPE products — so this feed is filtered to the full HPE Aruba Networking portfolio: ClearPass, AOS-8 mobility controllers, AOS-10 gateways and APs, Instant APs, AOS-CX and legacy AOS-Switch, Aruba Central, Fabric Composer and EdgeConnect/Silver Peak SD-WAN. Each entry links back to the official Aruba/HPE advisory when NVD carries the reference.

Latest Aruba EdgeConnect SD-WAN advisories

High7.2Aruba

High [CVE-2025-37183] Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

Vulnerabilities in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to perform SQL injection attacks. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the underlying database, potentially leading to unauthorized data access or data manipulation.

CVE-2025-37183
EdgeConnect SD-WAN
Jan 14, 2026
High7.2Aruba

High [CVE-2025-37127] vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the cryptographic logic used by HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to gain shell access. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system, potentially leading to unauthorized access and control over the affected systems.

CVE-2025-37127
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2025-37126] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system.

CVE-2025-37126
EdgeConnect SD-WAN
Sep 16, 2025
High7.5Aruba

High [CVE-2025-37125] EdgeConnect: broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS).

A broken access control vulnerability exists in HPE Aruba Networking EdgeConnect OS (ECOS). Successful exploitation could allow an attacker to bypass firewall protections, potentially leading to unauthorized traffic being handled improperly

CVE-2025-37125
EdgeConnect SD-WAN
Sep 16, 2025
High8.8Aruba

High [CVE-2025-37123] vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could

A vulnerability in the command-line interface of HPE Aruba Networking EdgeConnect SD-WAN Gateways could allow an authenticated remote attacker to escalate privileges. Successful exploitation of this vulnerability may enable the attacker to execute arbitrary system commands with root privileges on the underlying operating system.

CVE-2025-37123
EdgeConnect SD-WAN
Sep 16, 2025
High7.2Aruba

High [CVE-2024-41135] vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise

CVE-2024-41135
EdgeConnect SD-WAN
Jul 24, 2024
High7.2Aruba

High [CVE-2024-33519] vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could

A vulnerability in the web-based management interface of HPE Aruba Networking EdgeConnect SD-WAN gateway could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-33519
EdgeConnect SD-WAN
Jul 24, 2024
High8.1Aruba

High [CVE-2024-41914] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

CVE-2024-41914
EdgeConnect SD-WAN
Jul 24, 2024
High7.2Aruba

High [CVE-2024-22443] vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could

A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to conduct a server-side prototype pollution attack. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

CVE-2024-22443
EdgeConnect SD-WAN
Jul 24, 2024

← All Aruba advisories