First published: Tue Mar 21 2023(Updated: )
An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hpe Arubaos-cx | >=10.06.0000<10.06.0240 | |
Hpe Arubaos-cx | >=10.08.0000<=10.08.1070 | |
Hpe Arubaos-cx | >=10.09.0000<=10.09.1020 | |
Hpe Arubaos-cx | >=10.10.0000<10.10.1030 | |
Hpe Aruba Cx 10000-48y6 | ||
Hpe Aruba Cx 6200f 48g | ||
Hpe Aruba Cx 6200m 24g | ||
Hpe Aruba Cx 6300m 24p | ||
Hpe Aruba Cx 6300m 48g | ||
Hpe Aruba Cx 6405 | ||
Hpe Aruba Cx 6410 | ||
Hpe Aruba Cx 8320-32 | ||
Hpe Aruba Cx 8320-48p | ||
Hpe Aruba Cx 8325-32c | ||
Hpe Aruba Cx 8325-48y8c | ||
Hpe Aruba Cx 8360-12c | ||
Hpe Aruba Cx 8360-16y2c | ||
Hpe Aruba Cx 8360-24xf2c | ||
Hpe Aruba Cx 8360-32y4c | ||
Hpe Aruba Cx 8360-48xt4c | ||
Hpe Aruba Cx 8360-48y6c | ||
Hpe Aruba Cx 8400 | ||
Hpe Aruba Cx 9300 32d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1168 is an authenticated remote code execution vulnerability that exists in the AOS-CX Network Analytics Engine.
CVE-2023-1168 has a severity score of 8.8, which is classified as high.
CVE-2023-1168 affects Hpe Arubaos-cx versions 10.06.0000 to 10.06.0240, 10.08.0000 to 10.08.1070, 10.09.0000 to 10.09.1020, and 10.10.0000 to 10.10.1030.
Successful exploitation of CVE-2023-1168 allows an attacker to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch.
To fix CVE-2023-1168, it is recommended to update to a version of Hpe Arubaos-cx that is not vulnerable, such as versions outside the affected range mentioned earlier.