First published: Tue Mar 21 2023(Updated: )
An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Aruba Networks AOS-CX Firmware | >=10.06.0000<10.06.0240 | |
Aruba Networks AOS-CX Firmware | >=10.08.0000<=10.08.1070 | |
Aruba Networks AOS-CX Firmware | >=10.09.0000<=10.09.1020 | |
Aruba Networks AOS-CX Firmware | >=10.10.0000<10.10.1030 | |
HPE Aruba CX 10000-48Y6 | ||
Aruba CX 6200F | ||
HPE Aruba CX 6200M 24G | ||
HPE Aruba CX 6300M 24-port | ||
Aruba CX 6300 | ||
HPE Aruba CX 6405 | ||
HPE Aruba CX 6410 | ||
Aruba CX 8320 | ||
Aruba CX 8320 | ||
HPE Aruba 8325-32C | ||
Aruba CX 8325 | ||
Aruba CX 8360 | ||
Aruba CX 8360 | ||
HPE Aruba 8360-24XF2C | ||
Aruba CX 8360 | ||
Aruba CX 8360 | ||
Aruba CX 8360 | ||
HPE Aruba 8400X | ||
HPE Aruba CX 9300-32D |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1168 is an authenticated remote code execution vulnerability that exists in the AOS-CX Network Analytics Engine.
CVE-2023-1168 has a severity score of 8.8, which is classified as high.
CVE-2023-1168 affects Hpe Arubaos-cx versions 10.06.0000 to 10.06.0240, 10.08.0000 to 10.08.1070, 10.09.0000 to 10.09.1020, and 10.10.0000 to 10.10.1030.
Successful exploitation of CVE-2023-1168 allows an attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch.
To fix CVE-2023-1168, it is recommended to update to a version of Hpe Arubaos-cx that is not vulnerable, such as versions outside the affected range mentioned earlier.