Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code. Successful exploitation allows an attacker to login using only a username and password and successfully bypass MFA requirements in Aruba EdgeConnect Enterprise Orchestration Software version(s): Aruba EdgeConnect Enterprise Orchestrator (on-premises), Aruba EdgeConnect Enterprise Orchestrator-as-a-Service, Aruba EdgeConnect Enterprise Orchestrator-SP and Aruba EdgeConnect Enterprise Orchestrator Global Enterprise Tenant Orchestrators - Orchestrator 9.2.1.40179 and below, - Orchestrator 9.1.4.40436 and below, - Orchestrator 9.0.7.40110 and below, - Orchestrator 8.10.23.40015 and below, - Any older branches of Orchestrator not specifically mentioned.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-021.txt | Mitigation Vendor Advisory | 
| https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-021.txt | Mitigation Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
Configuration 3 (hide)
            
            
  | 
    
Configuration 4 (hide)
            
            
  | 
    
History
                    10 Apr 2025, 17:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-287 | 
21 Nov 2024, 07:26
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : unknown
         v3 : 4.8  | 
| Summary | 
        
        
  | 
|
| References | () https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-021.txt - Mitigation, Vendor Advisory | 
08 Aug 2023, 14:21
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-01-05 07:15
Updated : 2025-04-10 17:15
NVD link : CVE-2022-43528
Mitre link : CVE-2022-43528
CVE.ORG link : CVE-2022-43528
JSON object : View
Products Affected
                arubanetworks
- aruba_edgeconnect_enterprise_orchestrator
 
CWE
                