Known vulnerabilities in SD-WAN

Software: SD-WAN
Software CPE: cpe:2.3:h:aruba_networks:sd-wan:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 63
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SD-WAN SD-WAN is affected by 63 known vulnerabilities: 12 high, 3 medium, 48 low Critical High Medium Low

Vulnerabilities (63)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU118121 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-37145
CWE-22 Low
No
No
- 05.11.2025 SB2025110525
#VU118120 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-37144
CWE-22 Low
No
No
- 05.11.2025 SB2025110525
#VU118119 - Improper Access Control
CVE-2025-37143
CWE-284 Low
No
No
- 05.11.2025 SB2025110525
#VU118118 - Improper Access Control
CVE-2025-37142
CWE-284 Low
No
No
- 05.11.2025 SB2025110525
#VU118117 - Improper Access Control
CVE-2025-37141
CWE-284 Low
No
No
- 05.11.2025 SB2025110525
#VU118116 - Improper Access Control
CVE-2025-37140
CWE-284 Low
No
No
- 05.11.2025 SB2025110525
#VU118115 - Resource exhaustion
CVE-2025-37139
CWE-400 Low
No
No
- 05.11.2025 SB2025110525
#VU118114 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37138
CWE-78 Low
No
No
- 05.11.2025 SB2025110525
#VU118113 - Improper Access Control
CVE-2025-37137
CWE-284 Low
No
No
- 05.11.2025 SB2025110525
#VU118112 - Improper Access Control
CVE-2025-37136
CWE-284 Low
No
No
- 05.11.2025 SB2025110525
#VU118111 - Improper Access Control
CVE-2025-37135
CWE-284 Low
No
No
- 05.11.2025 SB2025110525
#VU118110 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37134
CWE-78 Low
No
No
- 05.11.2025 SB2025110525
#VU118109 - Unrestricted Upload of File with Dangerous Type
CVE-2025-37132
CWE-434 Low
No
No
- 05.11.2025 SB2025110525
#VU118108 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-37133
CWE-78 Low
No
No
- 05.11.2025 SB2025110525
#VU72656 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-22764
CWE-78 Low
No
No
8.7.0.0-2.3.0.9 01.03.2023 SB2023030113
#VU72650 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-22758
CWE-78 Low
No
No
8.7.0.0-2.3.0.9 01.03.2023 SB2023030113
#VU72651 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-22759
CWE-78 Low
No
No
8.7.0.0-2.3.0.9 01.03.2023 SB2023030113
#VU72652 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-22760
CWE-78 Low
No
No
8.7.0.0-2.3.0.9 01.03.2023 SB2023030113
#VU72653 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-22761
CWE-78 Low
No
No
8.7.0.0-2.3.0.9 01.03.2023 SB2023030113
#VU56064 - Out-of-bounds read
CVE-2021-3712
CWE-125 Medium
No
No
8.7.0.0-2.3.0.9 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 142 more


Showing elements 1 - 20 out of 63