Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-22788


Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.


Published

2023-05-08T15:15:10.440

Last Modified

2025-01-28T21:15:13.493

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System arubanetworks arubaos ≤ 10.3.1.0 Yes
Operating System hp instantos ≤ 6.4.4.8-4.2.4.20 Yes
Operating System hp instantos ≤ 6.5.4.23 Yes
Operating System hp instantos < 8.6.0.0 Yes
Operating System hp instantos ≤ 8.6.0.19 Yes
Operating System hp instantos ≤ 8.9.0.0 Yes
Operating System hp instantos ≤ 8.10.0.4 Yes

References