CVE Published: 03/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: hpe |
Vendor: Hewlett Packard Enterprise |
Product: Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central Status : PUBLISHED
CVE-2022-37908 Description
An authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromise the hardware chain of trust on the impacted controller.
Metrics
CVSS Version: 3.1 |
Base Score: 5.8 MEDIUM Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* NETWORK Attack Complexity (AC)* HIGH Privileges Required (PR)* HIGH User Interaction (UI)* NONE Scope (S)* CHANGED