CVE Feed

    Dashboard / CVE / CVE-2023-3718

    CVE-2023-3718

    An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.

    Published:Aug 1, 2023
    Last Modified:Nov 21, 2024
    EPS:Aug 1, 2023
    EPSS Score:0.01103
    CVSS Score:8.8

    Affected Products

    Vendor
    Hewlett Packard Enterprise
    Product
    Aruba Cx Switches
    Vendor
    Hpe
    Product
    Aruba Cx 10000-48y6
    Vendor
    Hpe
    Product
    Aruba Cx 4100i
    Vendor
    Hpe
    Product
    Aruba Cx 6000 12g
    Vendor
    Hpe
    Product
    Aruba Cx 6000 24g
    Vendor
    Hpe
    Product
    Aruba Cx 6000 48g
    Vendor
    Hpe
    Product
    Aruba Cx 6100
    Vendor
    Hpe
    Product
    Aruba Cx 6200f
    Vendor
    Hpe
    Product
    Aruba Cx 6200f 48g
    Vendor
    Hpe
    Product
    Aruba Cx 6200m
    Vendor
    Hpe
    Product
    Aruba Cx 6200m 24g
    Vendor
    Hpe
    Product
    Aruba Cx 6300m 24p
    Vendor
    Hpe
    Product
    Aruba Cx 6300m 48g
    Vendor
    Hpe
    Product
    Aruba Cx 6405
    Vendor
    Hpe
    Product
    Aruba Cx 6410
    Vendor
    Hpe
    Product
    Aruba Cx 8320-32
    Vendor
    Hpe
    Product
    Aruba Cx 8320-48p
    Vendor
    Hpe
    Product
    Aruba Cx 8325-32c
    Vendor
    Hpe
    Product
    Aruba Cx 8325-48y8c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-12c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-16y2c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-24xf2c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-32y4c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-48xt4c
    Vendor
    Hpe
    Product
    Aruba Cx 8360-48y6c
    Vendor
    Hpe
    Product
    Aruba Cx 8400
    Vendor
    Hpe
    Product
    Aruba Cx 9300 32d
    Vendor
    Hpe
    Product
    Arubaos-cx

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High