First published: Wed Mar 01 2023(Updated: )
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files in the underlying operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
arubanetworks ArubaOS | >=8.6.0.0<=8.6.0.19 | |
arubanetworks ArubaOS | >=8.10.0.0<=8.10.0.4 | |
arubanetworks ArubaOS | >=10.3.0.0<=10.3.1.0 | |
Aruba 7010 | ||
Aruba Networks 7030 | ||
Aruba Networks 7205 | ||
Aruba Networks 7210 | ||
Aruba Networks 7220 | ||
Aruba Networks 7240XM | ||
Aruba Networks 7280 | ||
Aruba Networks 9004 | ||
Arubanetworks 9004-LTE | ||
Aruba Networks 9012 | ||
Aruba Networks MC-VA | ||
Aruba Networks MC-VA-1K | ||
Aruba Networks MC-VA-250 | ||
Aruba Networks MC-VA-50 | ||
Aruba Networks MCR-HW-10K | ||
Arubanetworks MCR-HW-1K | ||
Aruba Networks MCR-HW-5K | ||
Aruba Networks MCR-VA 10K | ||
Aruba Networks MCR-VA-1K | ||
Aruba Networks MCR-VA-50 | ||
Aruba Networks MCR-VA 500 | ||
Aruba Networks MCR-VA 5K | ||
Aruba Networks SD-WAN | >=8.7.0.0-2.3.0.0<=8.7.0.0-2.3.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22774 is an authenticated path traversal vulnerability in the ArubaOS command line interface.
The severity of CVE-2023-22774 is high, with a CVSS score of 6.5.
Successful exploitation of CVE-2023-22774 allows an attacker with authenticated access to delete arbitrary files in the underlying operating system.
ArubaOS versions 8.6.0.0 to 8.6.0.19, 8.10.0.0 to 8.10.0.4, and 10.3.0.0 to 10.3.1.0 are affected by CVE-2023-22774.
To fix CVE-2023-22774, it is recommended to upgrade ArubaOS to a version that is not vulnerable.