Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22761


Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.


Published

2023-03-01T08:15:13.367

Last Modified

2024-11-21T07:45:22.497

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks sd-wan ≤ 8.7.0.0-2.3.0.8 Yes
Operating System arubanetworks arubaos ≤ 8.6.0.19 Yes
Operating System arubanetworks arubaos ≤ 8.10.0.4 Yes
Operating System arubanetworks arubaos ≤ 10.3.1.0 Yes

References