CVE Vulnerabilities

CVE-2023-1168

Published: Mar 22, 2023 | Modified: Feb 26, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.

Affected Software

NameVendorStart VersionEnd Version
Arubaos-cxHpe10.06.0000 (including)10.06.0240 (excluding)
Arubaos-cxHpe10.08.0000 (including)10.08.1070 (including)
Arubaos-cxHpe10.09.0000 (including)10.09.1020 (including)
Arubaos-cxHpe10.10.0000 (including)10.10.1030 (excluding)

References