CVE-2023-45625: Command Injection
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45625?
CVE-2023-45625 is a vulnerability that allows authenticated users to execute arbitrary commands as a privileged user on the affected operating system.
Which software is affected by CVE-2023-45625?
CVE-2023-45625 affects Arubanetworks ArubaOS versions 10.3.0.0 through 10.4.0.3, as well as Arubanetworks ArubaOS version 10.5.0.0 and Hp InstantOS versions 6.4.0.0 through 8.6.0.23, 8.10.0.0 through 8.10.0.9, and 8.11.0.0 through 8.11.2.0.
What is the severity of CVE-2023-45625?
CVE-2023-45625 has a severity rating of 7.2 (high).
How can an attacker exploit CVE-2023-45625?
An attacker with authenticated access can exploit CVE-2023-45625 by injecting arbitrary commands through the command line interface, allowing them to execute commands as a privileged user.
Is there a fix available for CVE-2023-45625?
Yes, a fix for CVE-2023-45625 may be available through a software update or patch released by the vendor. It is recommended to apply the latest updates to mitigate this vulnerability.