CVE-2023-22789

Multiple authenticated command injection vulnerabilitiesexist in the Aruba InstantOS and ArubaOS 10 command lineinterface. Successful exploitation of these vulnerabilitiesresult in the ability to execute arbitrary commands as aprivileged user on the underlying operating system.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
hpeCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
arubanetworksarubaos
10.3.0.0 ≤
𝑥
≤ 10.3.1.0
hpinstantos
6.4.0.0 ≤
𝑥
≤ 6.4.4.8-4.2.4.20
hpinstantos
6.5.0.0 ≤
𝑥
≤ 6.5.4.23
hpinstantos
8.4.0.0 ≤
𝑥
< 8.6.0.0
hpinstantos
8.6.0.0 ≤
𝑥
≤ 8.6.0.19
hpinstantos
8.7.0.0 ≤
𝑥
≤ 8.9.0.0
hpinstantos
8.10.0.0 ≤
𝑥
≤ 8.10.0.4
𝑥
= Vulnerable software versions