← Back

CVE-2022-23682

nvd nist
Published: Sep 6, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete switch compromise in ArubaOS-CX version(s): AOS-CX 10.09.xxxx: 10.09.1030 and below, AOS-CX 10.08.xxxx: 10.08.1030 and below, AOS-CX 10.06.xxxx: 10.06.0180 and below. Aruba has released upgrades for ArubaOS-CX Switch Devices that address these security vulnerabilities.

Affected (4)

1 product
Aos Cx
Configuration A
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 10000
All versions
Configuration B
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 8325
All versions
Configuration C
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 8320
All versions
Configuration D
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 9300
All versions
Configuration E
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 8360
All versions
Configuration F
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 6400
All versions
Configuration G
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 6300
All versions
Configuration H
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 6200f
All versions
Configuration I
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 6100
All versions
Configuration J
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 6000
All versions
Configuration K
1 platform
Running on/withPlatform Versions
Arubanetworks
Cx 4100i
All versions
Configuration L
4 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Arubanetworks
From 10.06.0000 to 10.06.0220
From 10.08.0000 to 10.08.1080
From 10.09.0000 to 10.09.1040
From 10.10.0000 to 10.10.0002
Running on/withPlatform Versions
Arubanetworks
Cx 8400
All versions

References (2)

Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.