← Back

CVE-2023-1168

nvd nist
Published: Mar 22, 2023Modified: Feb 26, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.

Affected (4)

Products: Hpe: Arubaos Cx
1 product
Arubaos Cx
Configuration A
4 vulnerable · 19 platform
Vulnerable SoftwareAffected Versions
Hpe
From 10.06.0000 to 10.06.0240
From 10.08.0000 to 10.08.1070
From 10.09.0000 to 10.09.1020
From 10.10.0000 to 10.10.1030
Running on/withPlatform Versions
Hpe
Aruba Cx 10000 48y6
All versions
Hpe
Aruba Cx 6200f 48g
All versions
Hpe
Aruba Cx 6200m 24g
All versions
Hpe
Aruba Cx 6300m 24p
All versions
Hpe
Aruba Cx 6300m 48g
All versions
Hpe
Aruba Cx 6405
All versions
Hpe
Aruba Cx 6410
All versions
Hpe
Aruba Cx 8320 32
All versions
Hpe
Aruba Cx 8320 48p
All versions
Hpe
Aruba Cx 8325 32c
All versions
Hpe
Aruba Cx 8325 48y8c
All versions
Hpe
Aruba Cx 8360 12c
All versions
Hpe
Aruba Cx 8360 16y2c
All versions
Hpe
Aruba Cx 8360 24xf2c
All versions
Hpe
Aruba Cx 8360 32y4c
All versions
Hpe
Aruba Cx 8360 48xt4c
All versions
Hpe
Aruba Cx 8360 48y6c
All versions
Hpe
Aruba Cx 8400
All versions
Hpe
Aruba Cx 9300 32d
All versions

References (2)

Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.