← Back

CVE-2023-3718

nvd nist
Published: Aug 1, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.

Affected (2)

Products: Hpe: Arubaos Cx
1 product
Arubaos Cx
Configuration A
2 vulnerable · 26 platform
Vulnerable SoftwareAffected Versions
Hpe
From 10.10.0000 to 10.10.1050
From 10.11.0000 to 10.11.1010
Running on/withPlatform Versions
Hpe
Aruba Cx 10000 48y6
All versions
Hpe
Aruba Cx 4100i
All versions
Hpe
Aruba Cx 6000 12g
All versions
Hpe
Aruba Cx 6000 24g
All versions
Hpe
Aruba Cx 6000 48g
All versions
Hpe
Aruba Cx 6100
All versions
Hpe
Aruba Cx 6200f
All versions
Hpe
Aruba Cx 6200f 48g
All versions
Hpe
Aruba Cx 6200m
All versions
Hpe
Aruba Cx 6200m 24g
All versions
Hpe
Aruba Cx 6300m 24p
All versions
Hpe
Aruba Cx 6300m 48g
All versions
Hpe
Aruba Cx 6405
All versions
Hpe
Aruba Cx 6410
All versions
Hpe
Aruba Cx 8320 32
All versions
Hpe
Aruba Cx 8320 48p
All versions
Hpe
Aruba Cx 8325 32c
All versions
Hpe
Aruba Cx 8325 48y8c
All versions
Hpe
Aruba Cx 8360 12c
All versions
Hpe
Aruba Cx 8360 16y2c
All versions
Hpe
Aruba Cx 8360 24xf2c
All versions
Hpe
Aruba Cx 8360 32y4c
All versions
Hpe
Aruba Cx 8360 48xt4c
All versions
Hpe
Aruba Cx 8360 48y6c
All versions
Hpe
Aruba Cx 8400
All versions
Hpe
Aruba Cx 9300 32d
All versions

References (2)

Source: security-alert@hpe.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.