CVE-2023-45626: High severity arubaos vulnerability
Published Nov 14, 2023
·Updated
An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.
Affected Software
5 affected components
Arubanetworks Arubaos>=10.3.0.0<10.4.0.3
Arubanetworks Arubaos=10.5.0.0
HP Instantos>=6.4.0.0<8.6.0.23
HP Instantos>=8.10.0.0<8.10.0.9
HP Instantos>=8.11.0.0<8.11.2.0
Event History
Nov 14, 2023
CVE Published
10:58 PM
Data Sourced
10:58 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-45626.
2
What is the severity level of CVE-2023-45626?
The severity level of CVE-2023-45626 is high.
3
Which software is affected by CVE-2023-45626?
The affected software includes Arubanetworks ArubaOS versions 10.3.0.0 to 10.4.0.3, 10.5.0.0, and Hp InstantOS versions 6.4.0.0 to 8.6.0.23, 8.10.0.0 to 8.10.0.9, and 8.11.0.0 to 8.11.2.0.
4
What can an attacker do with CVE-2023-45626?
An attacker can establish highly privileged persistent arbitrary code execution across boot cycles.
5
Is there a fix available for CVE-2023-45626?
It is recommended to refer to the Aruba Networks advisory at https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt for instructions on how to address the vulnerability.