CVE-2023-38484

Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that couldallow an attacker to execute arbitrary code early in the bootsequence. An attacker could exploit this vulnerability togain access to and change underlying sensitive informationin the affected controller leading to complete systemcompromise.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8 HIGH
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
hpeCNA
8 HIGH
NETWORK
HIGH
HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 45%
VendorProductVersion
arubanetworksarubaos
8.6.0.0 ≤
𝑥
< 8.6.0.22
arubanetworksarubaos
8.10.0.0 ≤
𝑥
< 8.10.0.7
arubanetworksarubaos
8.11.0.0 ≤
𝑥
< 8.11.1.1
arubanetworksarubaos
10.4.0.0 ≤
𝑥
< 10.4.0.2
𝑥
= Vulnerable software versions