Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN825
_____________________________________________________________________

DATE                : 05/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running HPE Aruba Networking SD-WAN
                    Orchestrator versions prior to 9.7.0.43264,
                             9.6.3.40140, 9.6.2.40210.
 
=====================================================================
https://csaf.arubanetworking.hpe.com/2026/hpe_aruba_networking_-_hpesbnw05100.txt
_____________________________________________________________________

HPE Aruba Networking Product Security Advisory
==============================================
Advisory ID: HPESBNW05100
CVE: CVE-2026-63455, CVE-2026-63456
Publication Date: 2026-AUG-4
Status: FINAL
Severity: CRITICAL
Revision: 1


Title
=====
Multiple Vulnerabilities in HPE Aruba Networking SD-WAN Orchestrator
9.6.x Software Branch Only


Overview
========
HPE Aruba Networking has released patches for HPE Networking SD-WAN
Orchestrator that addresses multiple security vulnerabilities in 
9.6.x Software branch.


Affected Products
=================
HPE Aruba Networking SD-WAN Orchestrator
    - SD-WAN Orchestrator 9.6.2.x: 9.6.2.40208 and below
    - SD-WAN Orchestrator 9.6.3.x: 9.6.3.40137 and below

No branches outside of 9.6.x.x are affected by these vulnerabilities.

 
Unaffected Products
=================
Any other HPE Aruba Networking products not specifically listed 
above, are not affected by these vulnerabilities.


Details
=======

Authentication bypass via spoofed HTTP headers Orchestrator REST API
(CVE-2026-63455, CVE-2026-63456)
- ---------------------------------------------------------------------
  Multiple vulnerabilities in the REST API interface of 
  HPE Networking SD-WAN Orchestrator could allow an unauthenticated 
  remote attacker to bypass web authentication mechanisms and access 
  system functions. Successful exploitation could allow an attacker 
  to view and modify potentially sensitive information on the target 
  system.

  Internal References: VULN-633, VULN-585, VULN-578, VULN-577, 
                       VULN-576 
  Severity: CRITICAL
  CVSSv3.1 Base Score: 9.8
  CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

  Discovery: These vulnerabilities were discovered and reported by 
  Christopher Alejandro (Moroco) through HPE Aruba Networking's Bug 
  Bounty program


Resolution
==========
In order to address the vulnerabilities described above for the 
affected software branches, HPE Aruba Networking recommends 
upgrading the software to one of the following versions 
(as applicable):

    - SD-WAN Orchestrator 9.7.0.x: 9.7.0.43264 and above
    - SD-WAN Orchestrator 9.6.3.x: 9.6.3.40140 and above
    - SD-WAN Orchestrator 9.6.2.x: 9.6.2.40210 and above

Software versions with resolution/fixes for the vulnerabilities 
covered above, can be downloaded from the HPE Networking Support 
Portal.   

https://networkingsupport.hpe.com/home/   

Product software versions that have reached End of Maintenance 
(EoM) are presumed to be affected by the vulnerabilities unless 
explicitly stated otherwise, and are not covered by this security 
advisory. HPE Aruba Networking does not evaluate or patch software 
branches that have reached their End of Support (EoST) milestone. 
For more information about HPE Aruba Networking EdgeConnect Product 
Lifecycle Policy, please visit: 

https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf 


Workaround
==========
To minimize the likelihood of an attacker exploiting these 
vulnerabilities, HPE Aruba Networking recommends that the CLI and 
web-based management interfaces be restricted to a dedicated layer 2 
segment/VLAN and/or controlled by firewall policies at layer 3 and 
above along with accounting controls for tracking and logging user 
activities and resource usage. As a best practice, it is recommended 
to configure IP-allow-listing for Orchestrator local users and API 
keys. You may contact HPE Services - HPE Aruba Networking for 
assistance if needed. For more information, please visit HPE Aruba 
Networking Support Portal at https://networkingsupport.hpe.com/home


Exploitation and Public Discussion
==================================
HPE Aruba Networking is not aware of any public discussion or exploit
code targeting these specific vulnerabilities as of the release date 
of the advisory.


Revision History
================
Revision 1 / 2026-AUG-4 / Initial release


HPE Aruba Networking SIRT Security Procedures 
==============================================
Complete information on reporting security vulnerabilities in HPE 
Aruba Networking products and obtaining assistance with security 
incidents is available at: 

http://www.hpe.com/support/security-response-policy

For reporting NEW HPE Aruba Networking security issues, email can 
be sent to hpe-networking-sirt@hpe.com. For sensitive information 
we encourage the use of PGP encryption. Our public keys can be 
found at: 

https://www.hpe.com/info/psrt-pgp-key 

(c) Copyright 2026 by Hewlett Packard Enterprise Development LP. 
This advisory may be redistributed freely after the release date 
given at the top of the text, provided that the redistributed copies
are complete and unmodified, including all data and version 
information.


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




