← Back

CVE-2023-38486

nvd nist
Published: Sep 6, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.4
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.5 / Impact: 5.9
Source: NVD

Description

A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned kernel images from executing. An attacker can use this vulnerability to execute arbitrary runtime operating systems, including unverified and unsigned OS images.

Affected (4)

1 product
Arubaos
Configuration A
4 vulnerable · 4 platform
Vulnerable SoftwareAffected Versions
Arubanetworks
From 10.4.0.0 to 10.4.0.2
From 8.10.0.0 to 8.10.0.7
From 8.11.0.0 to 8.11.1.1
From 8.6.0.0 to 8.6.0.22
Running on/withPlatform Versions
Arubanetworks
9004
All versions
Arubanetworks
9004 Lte
All versions
Arubanetworks
9012
All versions
Arubanetworks
9240
All versions

References (2)

Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.