CVE-2022-23682 describes multiple command injection vulnerabilities within the AOS-CX command line interface, impacting ArubaOS-CX switches running specific versions (10.09.1030 and below, 10.08.1030 and below, 10.06.0180 and below). This vulnerability carries a CVSS score of 7.8 (High), indicating that an authenticated attacker can execute arbitrary commands as root on the underlying operating system, leading to complete device compromise. While Aruba has released patches, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion, despite a single media mention unrelated to the vulnerability itself.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.06.0000, < 10.06.0220CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.08.0000, < 10.08.1080CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.09.0000, < 10.09.1040CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.10.0000, < 10.10.0002CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.