Lucene search

K
cvelistHpeCVELIST:CVE-2023-38486
HistorySep 06, 2023 - 5:48 p.m.

CVE-2023-38486 Hardware Root of Trust Bypass in 9200 and 9000 Series Controllers and Gateways

2023-09-0617:48:38
hpe
www.cve.org
3
vulnerability
secure boot implementation
bypass
aruba
9200
9000
controllers
gateways
unsigned kernel images
arbitrary execution
operating systems
os images

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.0%

A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned kernel images from executing. An attacker can use this vulnerability to execute arbitrary runtime operating systems, including unverified and unsigned OS images.

CNA Affected

[
  {
    "defaultStatus": "affected",
    "product": "9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways",
    "vendor": "Hewlett Packard Enterprise (HPE)",
    "versions": [
      {
        "lessThanOrEqual": "<=10.4.0.1",
        "status": "affected",
        "version": "ArubaOS 10.4.x.x",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "<=8.11.1.0",
        "status": "affected",
        "version": "ArubaOS 8.11.x.x",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "<=8.10.0.6",
        "status": "affected",
        "version": "ArubaOS 8.10.x.x",
        "versionType": "semver"
      },
      {
        "lessThanOrEqual": "<=8.6.0.21",
        "status": "affected",
        "version": "ArubaOS 8.6.x.x",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

AI Score

7.9

Confidence

High

EPSS

0

Percentile

9.0%

Related for CVELIST:CVE-2023-38486