CVE-2023-35972: Authenticated Remote Command Execution in ArubaOS Web-based Management Interface
An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35972?
CVE-2023-35972 is an authenticated remote command injection vulnerability in the ArubaOS web-based management interface.
What is the severity of CVE-2023-35972?
CVE-2023-35972 has a severity of 7.2 (High).
How does CVE-2023-35972 affect ArubaOS?
CVE-2023-35972 affects ArubaOS versions between 6.5.4.0 and 8.6.0.21, 8.7.0.0 and 8.10.0.7, 8.11.0.0 and 8.11.1.1, and 10.4.0.0 and 10.4.0.2.
What can an attacker do with CVE-2023-35972?
An attacker can exploit CVE-2023-35972 to execute arbitrary commands as a privileged user on the underlying operating system.
How can I fix CVE-2023-35972?
To fix CVE-2023-35972, update ArubaOS to a version that is not affected by the vulnerability.