CVE-2023-3718: Authenticated Command Injection Vulnerability in AOS-CX Command Line Interface
An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this command injection vulnerability?
The vulnerability ID for this command injection vulnerability is CVE-2023-3718.
What is the severity of CVE-2023-3718?
The severity of CVE-2023-3718 is high.
Which software is affected by CVE-2023-3718?
The affected software is Hpe Arubaos-cx versions 10.10.0000 to 10.10.1050 and 10.11.0000 to 10.11.1010.
How can the command injection vulnerability be exploited?
The command injection vulnerability can be exploited by executing arbitrary commands on the underlying operating system as a privileged user on the affected switch.
Is there a fix available for CVE-2023-3718?
Yes, it is recommended to update to a version of Hpe Arubaos-cx that is not vulnerable to this issue.