An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.
History

Tue, 22 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise
Hewlett Packard Enterprise aruba Cx Switches
CPEs cpe:2.3:a:hewlett_packard_enterprise:aruba_cx_switches:*:*:*:*:*:*:*:*
Vendors & Products Hewlett Packard Enterprise
Hewlett Packard Enterprise aruba Cx Switches
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published: 2023-08-01T18:25:10.262Z

Updated: 2024-10-22T20:29:41.391Z

Reserved: 2023-07-17T17:36:17.204Z

Link: CVE-2023-3718

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:57.375Z

cve-icon NVD

Status : Modified

Published: 2023-08-01T19:15:09.947

Modified: 2024-11-21T08:17:54.727

Link: CVE-2023-3718

cve-icon Redhat

No data.