CVE-2023-22758: Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22758.
What is the severity of CVE-2023-22758?
The severity of CVE-2023-22758 is high with a CVSS score of 7.2.
How does CVE-2023-22758 affect ArubaOS?
CVE-2023-22758 affects ArubaOS with versions ranging from 8.6.0.0 to 8.6.0.19, 8.7.0.0 to 8.7.0.0-2.3.0.8, 8.10.0.0 to 8.10.0.4, and 10.3.0.0 to 10.3.1.0.
What is the impact of CVE-2023-22758?
The successful exploitation of CVE-2023-22758 allows an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Is there a fix for CVE-2023-22758?
Yes, please refer to the official advisory from Aruba Networks for the recommended fix for CVE-2023-22758.