Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | EdgeConnect SD-WAN Orchestrator | Orchestrator 9.3.x ~ <=9.3.0 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-37422 | 8.1 HIGH | Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orch |
| CVE-2023-37423 | 8.1 HIGH | Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orch |
| CVE-2023-37424 | 8.1 HIGH | Unauthenticated Remote Code Execution in EdgeConnect SD-WAN Orchestrator Web-Based Managem |
| CVE-2023-37421 | 8.1 HIGH | Authenticated Stored Cross-Site Scripting Vulnerabilities (XSS) in EdgeConnect SD-WAN Orch |
| CVE-2023-37425 | 8.0 HIGH | Unauthenticated Stored Cross-Site Scripting Vulnerability (XSS) in EdgeConnect SD-WAN Orch |
| CVE-2023-37426 | 7.4 HIGH | Shared SSH Static Host Keys in EdgeConnect SD-WAN Orchestrator |
| CVE-2023-37427 | 7.2 HIGH | Authenticated Remote Code Execution in EdgeConnect SD-WAN Orchestrator Web-Based Managemen |
| CVE-2023-37428 | 7.2 HIGH | Authenticated Remote Code Execution via Path Traversal in EdgeConnect SD-WAN Orchestrator |
| CVE-2023-37431 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37438 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37437 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37436 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37435 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37434 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37433 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37432 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37430 | 6.5 MEDIUM | Authenticated SQL Injection Vulnerabilities in EdgeConnect SD-WAN Orchestrator Web-based M |
| CVE-2023-37439 | 6.1 MEDIUM | Reflected Cross Site Scripting in EdgeConnect SD-WAN Orchestrator Web Management Interface |
| CVE-2023-37440 | 5.5 MEDIUM | Authenticated Server-Side Request Forgery (SSRF) Leading to Information Disclosure |
No comments yet