CVE-2023-22789: Command Injection
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-22789?
CVE-2023-22789 is a vulnerability that allows authenticated users to execute arbitrary commands on the underlying operating system.
How does CVE-2023-22789 affect Aruba InstantOS?
CVE-2023-22789 affects Aruba InstantOS versions between 6.4.0.0 and 6.4.4.8-4.2.4.20, and versions between 6.5.0.0 and 6.5.4.23.
How does CVE-2023-22789 affect ArubaOS?
CVE-2023-22789 affects ArubaOS versions between 10.3.0.0 and 10.3.1.0.
What is the severity of CVE-2023-22789?
The severity of CVE-2023-22789 is rated as high with a CVSS score of 8.8.
How do I fix CVE-2023-22789?
To fix CVE-2023-22789, it is recommended to upgrade to a version that is not affected by the vulnerability.