CVE-2023-35977: Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface
Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2023-35977.
What is the severity of CVE-2023-35977?
The severity of CVE-2023-35977 is medium.
What is the affected software?
The affected software includes ArubaOS versions 6.5.4.0 to 8.6.0.21, 8.7.0.0 to 8.10.0.7, 8.11.0.0 to 8.11.1.1, and 10.4.0.0 to 10.4.0.2.
What is the impact of CVE-2023-35977?
Successful exploitation of CVE-2023-35977 could allow an authenticated attacker to access sensitive information beyond their authorized privilege level.
Is there any official reference for CVE-2023-35977?
Yes, you can find more information about CVE-2023-35977 in the official Aruba Networks security advisory: [ARUBA-PSA-2023-008.txt](https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt).