First published: Tue Nov 14 2023(Updated: )
There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Arubaos | >=10.3.0.0<10.4.0.3 | |
Arubanetworks Arubaos | =10.5.0.0 | |
Hp Instantos | >=6.4.0.0<8.6.0.23 | |
Hp Instantos | >=8.10.0.0<8.10.0.9 | |
Hp Instantos | >=8.11.0.0<8.11.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45617 is a vulnerability that allows arbitrary file deletion in the CLI service accessed by PAPI.
CVE-2023-45617 affects ArubaOS versions 10.3.0.0 to 10.4.0.3 and 10.5.0.0.
CVE-2023-45617 affects InstantOS versions 6.4.0.0 to 8.6.0.23, 8.10.0.0 to 8.10.0.9, and 8.11.0.0 to 8.11.2.0.
CVE-2023-45617 has a severity level of 8.2 (high).
To fix CVE-2023-45617, it is recommended to apply the necessary security patches provided by Aruba Networks or HP, depending on the affected product.