---
cve: "CVE-2022-37904"
severity: "MEDIUM"
cvss: 6.6
epss: "0.7%"
vendor: "Hewlett Packard Enterprise"
kev: false
exploited: false
published: "2022-12-12 13:15:12"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-27T04:02:05+02:00"
---

# CVE-2022-37904

> 6.6 MEDIUM

## Beschreibung

Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underlying operating system.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Hoch | good |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2022-37904) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
