CVE-2022-23679 describes a Cross-Site Request Forgery (CSRF) vulnerability in ArubaOS-CX Switches, affecting several versions across 10.06, 10.08, 10.09, and 10.10 branches. This flaw, rated 8.8 HIGH, allows an unauthenticated attacker to execute commands in the context of another user by tricking them into performing state-changing operations. While the potential impact is high (full confidentiality, integrity, and availability compromise), there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability. Aruba has released patches to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.06.0000, < 10.06.0210CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.08.0000, < 10.08.1070CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.09.0000, < 10.09.1030CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.10.0000, < 10.10.1000CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.