First published: Wed Jul 05 2023(Updated: )
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Arubaos | >=6.5.4.0<8.6.0.21 | |
Arubanetworks Arubaos | >=8.7.0.0<8.10.0.7 | |
Arubanetworks Arubaos | >=8.11.0.0<8.11.1.1 | |
Arubanetworks Arubaos | >=10.4.0.0<10.4.0.2 | |
Arubanetworks Mc-va-10 | ||
Arubanetworks Mc-va-1k | ||
Arubanetworks Mc-va-250 | ||
Arubanetworks Mc-va-50 | ||
Arubanetworks Mcr-va-10k | ||
Arubanetworks Mcr-va-1k | ||
Arubanetworks Mcr-va-50 | ||
Arubanetworks Mcr-va-500 | ||
Arubanetworks Mcr-va-5k | ||
Arubanetworks Sd-wan | ||
Arubanetworks Mcr-hw-10k | ||
Arubanetworks Mcr-hw-1k | ||
Arubanetworks Mcr-hw-5k |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface, allowing for the execution of arbitrary commands as a privileged user on the underlying operating system.
The severity of CVE-2023-35974 is high, with a severity value of 7.2.
ArubaOS versions 6.5.4.0 to 8.6.0.21, 8.7.0.0 to 8.10.0.7, 8.11.0.0 to 8.11.1.1, and 10.4.0.0 to 10.4.0.2 are affected by CVE-2023-35974.
Users are advised to upgrade to a patched version of ArubaOS and follow the recommendations provided by Aruba Networks.
More information about CVE-2023-35974 can be found at the following reference link: [Aruba Networks Advisory](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt).