CVE-2023-22757: Unauthenticated Buffer Overflow Vulnerabilities in ArubaOS Processes
There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this buffer overflow vulnerability?
The vulnerability ID for this buffer overflow vulnerability is CVE-2023-22757.
What is the severity rating for CVE-2023-22757?
The severity rating for CVE-2023-22757 is critical.
How can an attacker exploit CVE-2023-22757?
An attacker can exploit CVE-2023-22757 by sending specially crafted packets via the PAPI protocol, leading to unauthenticated remote code execution.
Which software versions are affected by CVE-2023-22757?
CVE-2023-22757 affects Arubanetworks SD-WAN versions 8.7.0.0-2.3.0.0 to 8.7.0.0-2.3.0.8, Arubanetworks ArubaOS versions 8.6.0.0 to 8.6.0.19, Arubanetworks ArubaOS versions 8.10.0.0 to 8.10.0.4, and Arubanetworks ArubaOS versions 10.3.0.0 to 10.3.1.0.
Is authentication required for an attacker to exploit CVE-2023-22757?
No, authentication is not required for an attacker to exploit CVE-2023-22757.