CVE-2023-1168: Authenticated Remote Code Execution in Aruba CX Switches
An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-1168?
CVE-2023-1168 is an authenticated remote code execution vulnerability that exists in the AOS-CX Network Analytics Engine.
How severe is CVE-2023-1168?
CVE-2023-1168 has a severity score of 8.8, which is classified as high.
Which software versions are affected by CVE-2023-1168?
CVE-2023-1168 affects Hpe Arubaos-cx versions 10.06.0000 to 10.06.0240, 10.08.0000 to 10.08.1070, 10.09.0000 to 10.09.1020, and 10.10.0000 to 10.10.1030.
How does successful exploitation of CVE-2023-1168 impact the system?
Successful exploitation of CVE-2023-1168 allows an attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch.
How can I fix CVE-2023-1168?
To fix CVE-2023-1168, it is recommended to update to a version of Hpe Arubaos-cx that is not vulnerable, such as versions outside the affected range mentioned earlier.