CVE-2023-22772: Authenticated Path Traversal in ArubaOS Web-based Management Interface Allows for Arbitrary File Deletion
An authenticated path traversal vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22772?
CVE-2023-22772 is an authenticated path traversal vulnerability in the ArubaOS web-based management interface.
What is the severity of CVE-2023-22772?
CVE-2023-22772 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2023-22772?
Arubanetworks Sd-wan, Arubanetworks Arubaos (versions 8.6.0.0 - 8.6.0.19), Arubanetworks Arubaos (versions 8.10.0.0 - 8.10.0.4), and Arubanetworks Arubaos (versions 10.3.0.0 - 10.3.1.0) are affected by CVE-2023-22772.
What is the impact of CVE-2023-22772?
Successful exploitation of CVE-2023-22772 allows the attacker to delete arbitrary files in the underlying operating system.
How can CVE-2023-22772 be fixed?
To fix CVE-2023-22772, it is recommended to apply the necessary security patches and updates provided by Arubanetworks.