Description
An authenticated remote code execution vulnerability
exists in the AOS-CX Network Analytics Engine. Successful
exploitation of this vulnerability results in the ability to
execute arbitrary code as a privileged user on the underlying
operating system, leading to a complete compromise of the
switch running AOS-CX.


Published: 2023-03-21
Score: 7.2 High
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-23450 An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Subscriptions

Hpe Aruba Cx 10000-48y6 Aruba Cx 6200f 48g Aruba Cx 6200m 24g Aruba Cx 6300m 24p Aruba Cx 6300m 48g Aruba Cx 6405 Aruba Cx 6410 Aruba Cx 8320-32 Aruba Cx 8320-48p Aruba Cx 8325-32c Aruba Cx 8325-48y8c Aruba Cx 8360-12c Aruba Cx 8360-16y2c Aruba Cx 8360-24xf2c Aruba Cx 8360-32y4c Aruba Cx 8360-48xt4c Aruba Cx 8360-48y6c Aruba Cx 8400 Aruba Cx 9300 32d Arubaos-cx
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-02-26T16:33:03.782Z

Reserved: 2023-03-03T16:58:46.073Z

Link: CVE-2023-1168

cve-icon Vulnrichment

Updated: 2024-08-02T05:40:57.963Z

cve-icon NVD

Status : Modified

Published: 2023-03-22T06:15:09.390

Modified: 2025-02-26T17:15:14.790

Link: CVE-2023-1168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses