MEDIUM · 4.3

CVE-2022-23688

Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the ...

Vulnerability Description

Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX Switches version(s): AOS-CX 10.09.xxxx: 10.09.1010 and below, AOS-CX 10.08.xxxx: 10.08.1050 and below, AOS-CX 10.06.xxxx: 10.06.0190 and below. Aruba has released upgrades for ArubaOS-CX Switch Devices that address these security vulnerabilities.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
ArubanetworksAos-Cx>= 10.06.0000, < 10.06.0200
ArubanetworksCx 10000-
ArubanetworksCx 8325-
ArubanetworksCx 8320-
ArubanetworksCx 9300-
ArubanetworksCx 8360-
ArubanetworksCx 6400-
ArubanetworksCx 6300-
ArubanetworksCx 6200F-
ArubanetworksCx 6100-
ArubanetworksCx 6000-
ArubanetworksCx 4100I-
ArubanetworksCx 8400-

References

FAQ

What is CVE-2022-23688?

CVE-2022-23688 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the ...

How severe is CVE-2022-23688?

CVE-2022-23688 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-23688?

Check the references section above for vendor advisories and patch information. Affected products include: Arubanetworks Aos-Cx, Arubanetworks Cx 10000, Arubanetworks Cx 8325, Arubanetworks Cx 8320, Arubanetworks Cx 9300.