Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-37184

Опубликовано: 14 янв. 2026
Источник: nvd
CVSS3: 6.5
CVSS3: 9.8
EPSS Низкий

Описание

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
Версия от 9.2.0 (включая) до 9.2.10 (включая)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
Версия от 9.3.0 (включая) до 9.3.6 (исключая)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
Версия от 9.4.0 (включая) до 9.4.3 (исключая)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:*:*:*:*:*:*:*:*
Версия от 9.5.0 (включая) до 9.5.6 (исключая)
cpe:2.3:a:arubanetworks:edgeconnect_sd-wan_orchestrator:9.6.0:*:*:*:*:*:*:*

EPSS

Процентиль: 23%
0.00076
Низкий

6.5 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 6.5
github
24 дня назад

A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.

EPSS

Процентиль: 23%
0.00076
Низкий

6.5 Medium

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-287