An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.



Project Subscriptions

Vendors Products
Hewlett Packard Enterprise Subscribe
Aruba Cx Switches Subscribe
Aruba Cx 10000-48y6 Subscribe
Aruba Cx 4100i Subscribe
Aruba Cx 6000 12g Subscribe
Aruba Cx 6000 24g Subscribe
Aruba Cx 6000 48g Subscribe
Aruba Cx 6100 Subscribe
Aruba Cx 6200f Subscribe
Aruba Cx 6200f 48g Subscribe
Aruba Cx 6200m Subscribe
Aruba Cx 6200m 24g Subscribe
Aruba Cx 6300m 24p Subscribe
Aruba Cx 6300m 48g Subscribe
Aruba Cx 6405 Subscribe
Aruba Cx 6410 Subscribe
Aruba Cx 8320-32 Subscribe
Aruba Cx 8320-48p Subscribe
Aruba Cx 8325-32c Subscribe
Aruba Cx 8325-48y8c Subscribe
Aruba Cx 8360-12c Subscribe
Aruba Cx 8360-16y2c Subscribe
Aruba Cx 8360-24xf2c Subscribe
Aruba Cx 8360-32y4c Subscribe
Aruba Cx 8360-48xt4c Subscribe
Aruba Cx 8360-48y6c Subscribe
Aruba Cx 8400 Subscribe
Aruba Cx 9300 32d Subscribe
Arubaos-cx Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-44353 An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 22 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Hewlett Packard Enterprise
Hewlett Packard Enterprise aruba Cx Switches
CPEs cpe:2.3:a:hewlett_packard_enterprise:aruba_cx_switches:*:*:*:*:*:*:*:*
Vendors & Products Hewlett Packard Enterprise
Hewlett Packard Enterprise aruba Cx Switches
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2024-10-22T20:29:41.391Z

Reserved: 2023-07-17T17:36:17.204Z

Link: CVE-2023-3718

cve-icon Vulnrichment

Updated: 2024-08-02T07:01:57.375Z

cve-icon NVD

Status : Modified

Published: 2023-08-01T19:15:09.947

Modified: 2024-11-21T08:17:54.727

Link: CVE-2023-3718

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses