CVE-2023-22760: Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22760?
CVE-2023-22760 refers to authenticated remote command injection vulnerabilities in the ArubaOS web-based management interface.
What is the severity of CVE-2023-22760?
CVE-2023-22760 has a severity rating of 7.2 out of 10, indicating a high severity.
Which software is affected by CVE-2023-22760?
Arubanetworks SD-WAN, Arubanetworks ArubaOS versions 8.6.0.0 to 8.6.0.19, Arubanetworks ArubaOS versions 8.7.0.0 to 8.7.0.0-2.3.0.8, and Arubanetworks ArubaOS versions 8.10.0.0 to 8.10.0.4 are affected by CVE-2023-22760.
How can CVE-2023-22760 be exploited?
Successful exploitation of CVE-2023-22760 allows an attacker to execute arbitrary commands as a privileged user on the underlying operating system.
Is there a fix for CVE-2023-22760?
To fix CVE-2023-22760, users are recommended to apply the necessary security patches provided by Aruba Networks as mentioned in their advisory.