CVE-2023-22750: Multiple Unauthenticated Command Injections in the PAPI Protocol
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22750?
CVE-2023-22750 is a vulnerability that allows unauthenticated remote code execution through command injection in Aruba Networks access point management protocol (PAPI) UDP port.
What is the severity of CVE-2023-22750?
The severity of CVE-2023-22750 is critical with a CVSS score of 9.8.
How can the CVE-2023-22750 vulnerability be exploited?
The CVE-2023-22750 vulnerability can be exploited by sending specially crafted packets to the PAPI UDP port (8211) of Aruba Networks access points.
Which software versions are affected by CVE-2023-22750?
The affected software versions include Arubanetworks Sd-wan 8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.8, Arubanetworks Arubaos 8.6.0.0 to 8.6.0.19, Arubanetworks Arubaos 8.10.0.0 to 8.10.0.4, and Arubanetworks Arubaos 10.3.0.0 to 10.3.1.0.
Where can I find more information about CVE-2023-22750?
More information about CVE-2023-22750 can be found at the following reference: [link](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-002.txt)