An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privileged user on the affected switch. This allows an attacker to fully compromise the underlying operating system on the device running AOS-CX.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos Cx | — | Upgrade affected switches to one of the following AOS-CX branches
and versions to resolve all the vulnerabilities described in the
details section:
- AOS-CX 10.12.xxxx: 10.12.0006 and above.
- AOS-CX 10.11.xxxx: 10.11.1021 and above.
- AOS-CX 10.10.xxxx: 10.10.1060 and above.
HPE Aruba Networking does not evaluate or patch AOS-CX software
branches that have reached their End of Maintenance (EoM)
milestone.
Supported branches as of the publication date of this advisory
are:
- AOS-CX 10.12.xxxx
- AOS-CX 10.11.xxxx
- AOS-CX 10.10.xxxx
- AOS-CX 10.06.xxxx
Please note that this advisory only applies to branches AOS-CX
10.10.xxxx and above.
For more information about HPE Aruba Networking's End of Support
policy visit:
https://www.arubanetworks.com/support-services/end-of-life/ | Feb 24, 2025 | Aug 1, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub