CVE-2023-35975: Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File Deletion
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to delete arbitrary files in the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-35975?
CVE-2023-35975 is an authenticated path traversal vulnerability in the ArubaOS command line interface.
How can this vulnerability be exploited?
Successful exploitation of CVE-2023-35975 allows an attacker to delete arbitrary files in the underlying operating system.
Which versions of ArubaOS are affected by CVE-2023-35975?
ArubaOS versions from 6.5.4.0 to 8.6.0.21, from 8.7.0.0 to 8.10.0.7, from 8.11.0.0 to 8.11.1.1, and 10.4.0.0 to 10.4.0.2 are affected by CVE-2023-35975.
What is the severity of CVE-2023-35975?
CVE-2023-35975 has a severity rating of 8.1 out of 10, classified as high.
How can I fix CVE-2023-35975?
Apply the necessary security patches provided by Aruba Networks as mentioned in the reference link.