CVE-2022-23690: Medium severity aruba networks aos-cx vulnerability
A vulnerability in the web-based management interface of AOS-CX could allow a remote unauthenticated attacker to fingerprint the exact version AOS-CX running on the switch. This allows an attacker to retrieve information which could be used to more precisely target the switch for further exploitation in ArubaOS-CX Switches version(s): AOS-CX 10.10.xxxx: 10.10.0002 and below, AOS-CX 10.09.xxxx: 10.09.1020 and below, AOS-CX 10.08.xxxx: 10.08.1060 and below, AOS-CX 10.06.xxxx: 10.06.0200 and below. Aruba has released upgrades for ArubaOS-CX Switch Devices that address this security vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23690?
CVE-2022-23690 has a medium severity level, indicating potential for exploitation if left unaddressed.
How do I fix CVE-2022-23690?
To fix CVE-2022-23690, update your AOS-CX software to the latest patched version provided by Aruba Networks.
What versions of AOS-CX are affected by CVE-2022-23690?
CVE-2022-23690 affects AOS-CX versions between 10.06.0000 and 10.10.0002.
Can CVE-2022-23690 be exploited by authenticated users?
No, CVE-2022-23690 can be exploited by remote unauthenticated attackers, which increases its risk.
What information can be leaked due to CVE-2022-23690?
CVE-2022-23690 allows attackers to fingerprint the AOS-CX version, which can help in further targeted attacks.