CVE-2023-22761: Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22761?
CVE-2023-22761 is an authenticated remote command injection vulnerability in the ArubaOS web-based management interface.
How does CVE-2023-22761 impact the system?
Successful exploitation of CVE-2023-22761 allows an attacker to execute arbitrary commands as a privileged user on the underlying operating system, potentially leading to full control of the system.
Which software versions are affected by CVE-2023-22761?
The ArubaOS versions between 8.6.0.0 and 8.6.0.19, between 8.7.0.0 and 8.7.0.0-2.3.0.8, between 8.10.0.0 and 8.10.0.4, and between 10.3.0.0 and 10.3.1.0 are affected by CVE-2023-22761.
What is the severity of CVE-2023-22761?
CVE-2023-22761 has a severity rating of 7.2 (high).
How can I mitigate CVE-2023-22761?
It is recommended to update the affected ArubaOS software versions to the latest patched versions provided by Aruba Networks.