An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | In order to address the vulnerability in the affected release branches and switch platforms described above, it is recommended to upgrade the software to one of the following versions (as applicable): - AOS-CX 10.11.xxxx: 10.11.0001 and above. - AOS-CX 10.10.xxxx: 10.10.1030 and above. - AOS-CX 10.06.xxxx: 10.06.0240 and above. Aruba does not evaluate or patch AOS-CX firmware versions that have reached their End of Support (EoS) milestone. Supported versions as of the publication date of this advisory are: - AOS-CX 10.11.xxxx - AOS-CX 10.10.xxxx - AOS-CX 10.06.xxxx For more information about Aruba's End of Support policy visit: https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | Mar 21, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub