CVE-2022-23689: Medium severity aruba networks aos-cx vulnerability
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch in ArubaOS-CX Switches version(s): AOS-CX 10.09.xxxx: 10.09.1010 and below, AOS-CX 10.08.xxxx: 10.08.1050 and below, AOS-CX 10.06.xxxx: 10.06.0190 and below. Aruba has released upgrades for ArubaOS-CX Switch Devices that address these security vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23689?
The severity of CVE-2022-23689 is currently unknown but it poses potential risks to the AOS-CX LLDP service and management plane.
How do I fix CVE-2022-23689?
To fix CVE-2022-23689, upgrade ArubaOS-CX to a version later than 10.10.0002 or apply available security patches.
Which versions of ArubaOS-CX are affected by CVE-2022-23689?
CVE-2022-23689 affects ArubaOS-CX versions from 10.06.0000 to 10.10.0002.
What are the potential impacts of CVE-2022-23689?
The exploitation of CVE-2022-23689 may lead to availability issues in the AOS-CX LLDP service and the management interface of the switch.
How can I determine if my ArubaOS-CX switch is vulnerable to CVE-2022-23689?
To determine if your ArubaOS-CX switch is vulnerable to CVE-2022-23689, check if it is running a version between 10.06.0000 and 10.10.0002.