There are buffer overflow vulnerabilities in multiple underlying operating system processes that could lead to unauthenticated remote code execution by sending specially crafted packets via the PAPI protocol. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos 10 | — | Please note that due the complexity of code changes involved it was not possible to backport changes for these specific vulnerabilities (CVE-2023-22753, CVE-2023-22754, CVE-2023-22755, CVE-2023-22756, CVE-2023-22757) to ArubaOS 8.6.x. Customers using firmware versions in the 8.6.x branch are urged to implement the workaround listed in this section or to upgrade to ArubaOS 8.10.x. | Jan 14, 2025 | Feb 28, 2023 |
| Aruba Aos 8 | — | Please note that due the complexity of code changes involved it was not possible to backport changes for these specific vulnerabilities (CVE-2023-22753, CVE-2023-22754, CVE-2023-22755, CVE-2023-22756, CVE-2023-22757) to ArubaOS 8.6.x. Customers using firmware versions in the 8.6.x branch are urged to implement the workaround listed in this section or to upgrade to ArubaOS 8.10.x. | Jan 14, 2025 | Feb 28, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub