CVE-2023-35972

An authenticated remote command injection vulnerabilityexists in the ArubaOS web-based management interface.Successful exploitation of this vulnerability results in theability to execute arbitrary commands as a privileged useron the underlying operating system. This allows an attackerto fully compromise the underlying operating system on thedevice running ArubaOS.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
hpeCNA
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---