Description

An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.



Published: 2023-08-01
Score: 8.8 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44353 An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.
History

Tue, 22 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise
Hewlett Packard Enterprise aruba Cx Switches
CPEs cpe:2.3:a:hewlett_packard_enterprise:aruba_cx_switches:*:*:*:*:*:*:*:*
Vendors & Products Hewlett Packard Enterprise
Hewlett Packard Enterprise aruba Cx Switches
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Hewlett Packard Enterprise Aruba Cx Switches
Hpe Aruba Cx 10000-48y6 Aruba Cx 4100i Aruba Cx 6000 12g Aruba Cx 6000 24g Aruba Cx 6000 48g Aruba Cx 6100 Aruba Cx 6200f Aruba Cx 6200f 48g Aruba Cx 6200m Aruba Cx 6200m 24g Aruba Cx 6300m 24p Aruba Cx 6300m 48g Aruba Cx 6405 Aruba Cx 6410 Aruba Cx 8320-32 Aruba Cx 8320-48p Aruba Cx 8325-32c Aruba Cx 8325-48y8c Aruba Cx 8360-12c Aruba Cx 8360-16y2c Aruba Cx 8360-24xf2c Aruba Cx 8360-32y4c Aruba Cx 8360-48xt4c Aruba Cx 8360-48y6c Aruba Cx 8400 Aruba Cx 9300 32d Arubaos-cx
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-10-22T20:29:41.391Z

Reserved: 2023-07-17T17:36:17.204Z

Link: CVE-2023-3718

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:57.375Z

cve-icon NVD

Status : Modified

Published: 2023-08-01T19:15:09.947

Modified: 2024-11-21T08:17:54.727

Link: CVE-2023-3718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses