CVE Vulnerabilities

CVE-2023-1168

Published: Mar 22, 2023 | Modified: Nov 07, 2023
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.

Affected Software

Name Vendor Start Version End Version
Arubaos-cx Hpe 10.06.0000 (including) 10.06.0240 (excluding)
Arubaos-cx Hpe 10.08.0000 (including) 10.08.1070 (including)
Arubaos-cx Hpe 10.09.0000 (including) 10.09.1020 (including)
Arubaos-cx Hpe 10.10.0000 (including) 10.10.1030 (excluding)

References