Lucene search

K
nvd[email protected]NVD:CVE-2023-38486
HistorySep 06, 2023 - 6:15 p.m.

CVE-2023-38486

2023-09-0618:15:08
CWE-863
web.nvd.nist.gov
4
vulnerability
secure boot
aruba 9200
aruba 9000
bypass
security controls
unsigned kernel images
arbitrary execution
operating systems

CVSS3

6.4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned kernel images from executing. An attacker can use this vulnerability to execute arbitrary runtime operating systems, including unverified and unsigned OS images.

Affected configurations

Nvd
Node
arubanetworksarubaosRange8.6.0.08.6.0.22
OR
arubanetworksarubaosRange8.10.0.08.10.0.7
OR
arubanetworksarubaosRange8.11.0.08.11.1.1
OR
arubanetworksarubaosRange10.4.0.010.4.0.2
AND
arubanetworks9004Match-
OR
arubanetworks9004-lteMatch-
OR
arubanetworks9012Match-
OR
arubanetworks9240Match-
VendorProductVersionCPE
arubanetworksarubaos*cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
arubanetworks9004-cpe:2.3:h:arubanetworks:9004:-:*:*:*:*:*:*:*
arubanetworks9004-lte-cpe:2.3:h:arubanetworks:9004-lte:-:*:*:*:*:*:*:*
arubanetworks9012-cpe:2.3:h:arubanetworks:9012:-:*:*:*:*:*:*:*
arubanetworks9240-cpe:2.3:h:arubanetworks:9240:-:*:*:*:*:*:*:*

CVSS3

6.4

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

9.0%

Related for NVD:CVE-2023-38486