CVE-2023-3718

An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.



Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
hpearubaos-cx
10.10.0000 ≤
𝑥
≤ 10.10.1050
hpearubaos-cx
10.11.0000 ≤
𝑥
≤ 10.11.1010
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
hewlett_packard_enterprisearuba_cx_switches
10.11 ≤
𝑥
≤ 10.11.1010
ADP
hewlett_packard_enterprisearuba_cx_switches
10.10 ≤
𝑥
≤ 10.10.1050
ADP