First published: Tue Feb 28 2023(Updated: )
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
ArubaOS | >=8.6.0.0<=8.6.0.19 | |
ArubaOS | >=8.10.0.0<=8.10.0.4 | |
ArubaOS | >=10.3.0.0<=10.3.1.0 | |
Aruba 7010 | ||
Aruba Networks 7030 | ||
Aruba Networks 7205 | ||
Aruba Networks 7210 | ||
Aruba Networks 7220 | ||
Aruba Networks 7240XM | ||
Aruba Networks 7280 | ||
Aruba Networks 9004 | ||
Arubanetworks 9004-LTE | ||
Aruba Networks 9012 | ||
Aruba Networks MC-VA | ||
Aruba Networks MC-VA-1K | ||
Aruba Networks MC-VA-250 | ||
Aruba Networks MC-VA-50 | ||
Aruba Networks MCR-HW-10K | ||
Arubanetworks MCR-HW-1K | ||
Aruba Networks MCR-HW-5K | ||
Aruba Networks MCR-VA 10K | ||
Aruba Networks MCR-VA-1K | ||
Aruba Networks MCR-VA-50 | ||
Aruba Networks MCR-VA 500 | ||
Aruba Networks MCR-VA 5K | ||
Aruba Networks SD-WAN | >=8.7.0.0-2.3.0.0<=8.7.0.0-2.3.0.8 | |
All of | ||
Any of | ||
ArubaOS | >=8.6.0.0<=8.6.0.19 | |
ArubaOS | >=8.10.0.0<=8.10.0.4 | |
ArubaOS | >=10.3.0.0<=10.3.1.0 | |
Any of | ||
Aruba 7010 | ||
Aruba Networks 7030 | ||
Aruba Networks 7205 | ||
Aruba Networks 7210 | ||
Aruba Networks 7220 | ||
Aruba Networks 7240XM | ||
Aruba Networks 7280 | ||
Aruba Networks 9004 | ||
Arubanetworks 9004-LTE | ||
Aruba Networks 9012 | ||
Aruba Networks MC-VA | ||
Aruba Networks MC-VA-1K | ||
Aruba Networks MC-VA-250 | ||
Aruba Networks MC-VA-50 | ||
Aruba Networks MCR-HW-10K | ||
Arubanetworks MCR-HW-1K | ||
Aruba Networks MCR-HW-5K | ||
Aruba Networks MCR-VA 10K | ||
Aruba Networks MCR-VA-1K | ||
Aruba Networks MCR-VA-50 | ||
Aruba Networks MCR-VA 500 | ||
Aruba Networks MCR-VA 5K |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22773 is a vulnerability that allows authenticated path traversal in the ArubaOS command line interface, leading to the ability to delete arbitrary files in the underlying operating system.
Software versions 8.6.0.0 to 8.6.0.19, 8.10.0.0 to 8.10.0.4, and 10.3.0.0 to 10.3.1.0 of ArubaOS are affected by CVE-2023-22773.
CVE-2023-22773 is classified as a high severity vulnerability with a severity value of 6.5.
To fix CVE-2023-22773, it is recommended to update ArubaOS to a version that is not affected by the vulnerability.
You can find more information about CVE-2023-22773 in the Aruba Networks security advisory ARUBA-PSA-2023-002.