CVE-2023-22758

Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
hpeCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 58%
VendorProductVersion
arubanetworkssd-wan
8.7.0.0-2.3.0.0 ≤
𝑥
≤ 8.7.0.0-2.3.0.8
arubanetworksarubaos
8.6.0.0 ≤
𝑥
≤ 8.6.0.19
arubanetworksarubaos
8.10.0.0 ≤
𝑥
≤ 8.10.0.4
arubanetworksarubaos
10.3.0.0 ≤
𝑥
≤ 10.3.1.0
𝑥
= Vulnerable software versions