Vulnerability Description
An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hpe | Arubaos-Cx | >= 10.10.0000, <= 10.10.1050 |
| Hpe | Aruba Cx 10000-48Y6 | - |
| Hpe | Aruba Cx 4100I | - |
| Hpe | Aruba Cx 6000 12G | - |
| Hpe | Aruba Cx 6000 24G | - |
| Hpe | Aruba Cx 6000 48G | - |
| Hpe | Aruba Cx 6100 | - |
| Hpe | Aruba Cx 6200F | - |
| Hpe | Aruba Cx 6200F 48G | - |
| Hpe | Aruba Cx 6200M | - |
| Hpe | Aruba Cx 6200M 24G | - |
| Hpe | Aruba Cx 6300M 24P | - |
| Hpe | Aruba Cx 6300M 48G | - |
| Hpe | Aruba Cx 6405 | - |
| Hpe | Aruba Cx 6410 | - |
| Hpe | Aruba Cx 8320-32 | - |
| Hpe | Aruba Cx 8320-48P | - |
| Hpe | Aruba Cx 8325-32C | - |
| Hpe | Aruba Cx 8325-48Y8C | - |
| Hpe | Aruba Cx 8360-12C | - |
Related Weaknesses (CWE)
References
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txtMitigationVendor Advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-010.txtMitigationVendor Advisory
FAQ
What is CVE-2023-3718?
CVE-2023-3718 is a vulnerability with a CVSS score of 8.8 (HIGH). An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the...
How severe is CVE-2023-3718?
CVE-2023-3718 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-3718?
Check the references section above for vendor advisories and patch information. Affected products include: Hpe Arubaos-Cx, Hpe Aruba Cx 10000-48Y6, Hpe Aruba Cx 4100I, Hpe Aruba Cx 6000 12G, Hpe Aruba Cx 6000 24G.