Risques
- Atteinte à l'intégrité des données
- Atteinte à la confidentialité des données
- Contournement de la politique de sécurité
- Déni de service à distance
- Exécution de code arbitraire à distance
- Falsification de requêtes côté serveur (SSRF)
- Élévation de privilèges
Systèmes affectés
- EdgeConnect SD-WAN Gateways versions 9.4.x.x antérieures à ECOS 9.4.9.0
- EdgeConnect SD-WAN Gateways versions 9.5.x.x antérieures à ECOS 9.5.9.0
- EdgeConnect SD-WAN Gateways versions 9.6.x.x antérieures à ECOS 9.6.4.0
- EdgeConnect SD-WAN Gateways versions 9.7.x.x antérieures à ECOS 9.7.1.0
- EdgeConnect SD-WAN Orchestrator versions 9.4.x antérieures à Orchestrator 9.4.11
- EdgeConnect SD-WAN Orchestrator versions 9.5.x antérieures à Orchestrator 9.5.9
- EdgeConnect SD-WAN Orchestrator versions 9.6.x antérieures à Orchestrator 9.6.4
- EdgeConnect SD-WAN Orchestrator versions 9.7.x antérieures à Orchestrator 9.7.1
Résumé
De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Solutions
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Documentation
- Bulletin de sécurité HPE Aruba Networking HPESBNW05135 du 15 septembre 2026 https://csaf.arubanetworking.hpe.com/2026/hpe_networking_-_hpesbnw05135.txt
- Référence CVE CVE-2024-32664 https://www.cve.org/CVERecord?id=CVE-2024-32664
- Référence CVE CVE-2026-76669 https://www.cve.org/CVERecord?id=CVE-2026-76669
- Référence CVE CVE-2026-76670 https://www.cve.org/CVERecord?id=CVE-2026-76670
- Référence CVE CVE-2026-76672 https://www.cve.org/CVERecord?id=CVE-2026-76672
- Référence CVE CVE-2026-76673 https://www.cve.org/CVERecord?id=CVE-2026-76673
- Référence CVE CVE-2026-76674 https://www.cve.org/CVERecord?id=CVE-2026-76674
- Référence CVE CVE-2026-76675 https://www.cve.org/CVERecord?id=CVE-2026-76675
- Référence CVE CVE-2026-76676 https://www.cve.org/CVERecord?id=CVE-2026-76676
- Référence CVE CVE-2026-76677 https://www.cve.org/CVERecord?id=CVE-2026-76677
- Référence CVE CVE-2026-76678 https://www.cve.org/CVERecord?id=CVE-2026-76678
- Référence CVE CVE-2026-76679 https://www.cve.org/CVERecord?id=CVE-2026-76679
- Référence CVE CVE-2026-76680 https://www.cve.org/CVERecord?id=CVE-2026-76680
- Référence CVE CVE-2026-76681 https://www.cve.org/CVERecord?id=CVE-2026-76681
- Référence CVE CVE-2026-76682 https://www.cve.org/CVERecord?id=CVE-2026-76682
- Référence CVE CVE-2026-76683 https://www.cve.org/CVERecord?id=CVE-2026-76683
- Référence CVE CVE-2026-76684 https://www.cve.org/CVERecord?id=CVE-2026-76684
- Référence CVE CVE-2026-76685 https://www.cve.org/CVERecord?id=CVE-2026-76685
- Référence CVE CVE-2026-76686 https://www.cve.org/CVERecord?id=CVE-2026-76686
- Référence CVE CVE-2026-76687 https://www.cve.org/CVERecord?id=CVE-2026-76687
- Référence CVE CVE-2026-76688 https://www.cve.org/CVERecord?id=CVE-2026-76688
- Référence CVE CVE-2026-76689 https://www.cve.org/CVERecord?id=CVE-2026-76689
- Référence CVE CVE-2026-76690 https://www.cve.org/CVERecord?id=CVE-2026-76690
- Référence CVE CVE-2026-76691 https://www.cve.org/CVERecord?id=CVE-2026-76691
- Référence CVE CVE-2026-76692 https://www.cve.org/CVERecord?id=CVE-2026-76692
- Référence CVE CVE-2026-76693 https://www.cve.org/CVERecord?id=CVE-2026-76693
- Référence CVE CVE-2026-76694 https://www.cve.org/CVERecord?id=CVE-2026-76694
- Référence CVE CVE-2026-76695 https://www.cve.org/CVERecord?id=CVE-2026-76695
- Référence CVE CVE-2026-76696 https://www.cve.org/CVERecord?id=CVE-2026-76696
- Référence CVE CVE-2026-76697 https://www.cve.org/CVERecord?id=CVE-2026-76697
- Référence CVE CVE-2026-76698 https://www.cve.org/CVERecord?id=CVE-2026-76698
- Référence CVE CVE-2026-76699 https://www.cve.org/CVERecord?id=CVE-2026-76699
- Référence CVE CVE-2026-76700 https://www.cve.org/CVERecord?id=CVE-2026-76700
- Référence CVE CVE-2026-76701 https://www.cve.org/CVERecord?id=CVE-2026-76701
- Référence CVE CVE-2026-76702 https://www.cve.org/CVERecord?id=CVE-2026-76702
- Référence CVE CVE-2026-76703 https://www.cve.org/CVERecord?id=CVE-2026-76703
- Référence CVE CVE-2026-76704 https://www.cve.org/CVERecord?id=CVE-2026-76704
- Référence CVE CVE-2026-76705 https://www.cve.org/CVERecord?id=CVE-2026-76705
- Référence CVE CVE-2026-76706 https://www.cve.org/CVERecord?id=CVE-2026-76706
- Référence CVE CVE-2026-76707 https://www.cve.org/CVERecord?id=CVE-2026-76707