CVE-2023-22777: Authenticated Information Disclosure in ArubaOS Web-based Management Interface
Published Feb 28, 2023
·Updated
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.
Affected Software
4 affected components
Arubanetworks Sd-wan>=8.7.0.0-2.3.0.0<=8.7.0.0-2.3.0.8
Arubanetworks Arubaos>=8.6.0.0<=8.6.0.19
Arubanetworks Arubaos>=8.10.0.0<=8.10.0.4
Arubanetworks Arubaos>=10.3.0.0<=10.3.1.0
Event History
Feb 28, 2023
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-22777?
CVE-2023-22777 is an authenticated information disclosure vulnerability in the ArubaOS web-based management interface.
2
How does CVE-2023-22777 affect ArubaOS?
CVE-2023-22777 allows an authenticated attacker to read arbitrary files in the underlying operating system of ArubaOS.
3
What is the severity of CVE-2023-22777?
CVE-2023-22777 has a severity rating of 6.5 (medium).
4
Which versions of ArubaOS are affected by CVE-2023-22777?
ArubaOS versions 8.6.0.0 to 8.6.0.19, 8.7.0.0 to 8.7.0.0-2.3.0.8, 8.10.0.0 to 8.10.0.4, and 10.3.0.0 to 10.3.1.0 are affected by CVE-2023-22777.
5
How can CVE-2023-22777 be fixed?
Apply the vendor-supplied patches or updates for ArubaOS to fix CVE-2023-22777.