Lucene search

K
nvd[email protected]NVD:CVE-2022-23683
HistorySep 06, 2022 - 6:15 p.m.

CVE-2022-23683

2022-09-0618:15:11
CWE-78
web.nvd.nist.gov
cve-2022-23683
authenticated command injection
aos-cx
network analytics engine
nae scripts
arubaos-cx
switches
security vulnerabilities
operating system
aruba

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

46.1%

Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX in ArubaOS-CX Switches version(s): AOS-CX 10.10.xxxx: 10.10.0002 and below, AOS-CX 10.09.xxxx: 10.09.1030 and below, AOS-CX 10.08.xxxx: 10.08.1070 and below, AOS-CX 10.06.xxxx: 10.06.0210 and below. Aruba has released upgrades for ArubaOS-CX Switch Devices that address these security vulnerabilities.

Affected configurations

NVD
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_10000Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_8325Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_8320Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_9300Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_8360Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_6400Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_6300Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_6200fMatch-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_6100Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_6000Match-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_4100iMatch-
Node
arubanetworksaos-cxRange10.06.000010.06.0220
OR
arubanetworksaos-cxRange10.08.000010.08.1080
OR
arubanetworksaos-cxRange10.09.000010.09.1040
OR
arubanetworksaos-cxRange10.10.000010.10.1000
AND
arubanetworkscx_8400Match-

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

46.1%

Related for NVD:CVE-2022-23683