Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-39268


A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.


Published

2023-08-29T20:15:09.830

Last Modified

2024-11-21T08:15:01.323

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hpe arubaos-switch < a.15.16.0026 Yes
Operating System hpe arubaos-switch < 16.04.0027 Yes
Operating System hpe arubaos-switch < 16.08.0027 Yes
Operating System hpe arubaos-switch < 16.10.0024 Yes
Operating System hpe arubaos-switch < 16.11.0013 Yes
Hardware arubanetworks aruba_2530 - No
Hardware arubanetworks aruba_2530ya - No
Hardware arubanetworks aruba_2530yb - No
Hardware arubanetworks aruba_2540 - No
Hardware arubanetworks aruba_2920 - No
Hardware arubanetworks aruba_2930f - No
Hardware arubanetworks aruba_2930m - No
Hardware arubanetworks aruba_3810m - No
Hardware arubanetworks aruba_5406r_zl2 - No
Hardware arubanetworks aruba_5412r_zl2 - No

References