CVE-2022-23677

A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
hpeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 93%
VendorProductVersion
arubanetworks5406r_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks5406r_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks5406r_firmware
16.03.0 ≤
𝑥
< 16.04.0024
arubanetworks5406r_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks5406r_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks5406r_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks5406r_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks2920_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2920_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2920_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2920_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2920_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks2920_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks2920_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks2930f_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2930f_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2930f_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2930f_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2930f_firmware
16.09.0 ≤
𝑥
≤ 16.09.0020
arubanetworks2930f_firmware
16.10.0 ≤
𝑥
≤ 16.10.0020
arubanetworks2930f_firmware
16.11.0 ≤
𝑥
≤ 16.11.0004
arubanetworks2930m_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2930m_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2930m_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2930m_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2930m_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks2930m_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks2930m_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks2530_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2530_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2530_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2530_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2530_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks2530_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks2530_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks2540_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2540_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2540_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2540_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2540_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks2540_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks2540_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks5412r_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks5412r_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks5412r_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks5412r_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks5412r_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks5412r_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks5412r_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks2615_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2615_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2615_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2615_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2615_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks2615_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks2615_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks2620_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2620_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2620_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2620_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2620_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks2620_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks2620_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks2915_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks2915_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks2915_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks2915_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks2915_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks2915_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks2915_firmware
16.11.0 ≤
𝑥
< 16.11.0004
arubanetworks3810m_firmware
15.00.0 ≤
𝑥
≤ 15.16.0023
arubanetworks3810m_firmware
16.01.0 ≤
𝑥
< 16.02.0034
arubanetworks3810m_firmware
16.03.0 ≤
𝑥
≤ 16.04.0024
arubanetworks3810m_firmware
16.05.0 ≤
𝑥
< 16.08.0025
arubanetworks3810m_firmware
16.09.0 ≤
𝑥
< 16.09.0020
arubanetworks3810m_firmware
16.10.0 ≤
𝑥
< 16.10.0020
arubanetworks3810m_firmware
16.11.0 ≤
𝑥
< 16.11.0004
𝑥
= Vulnerable software versions