CVE-2022-23684 is a privilege escalation vulnerability in the web-based management interface of ArubaOS-CX switches, affecting versions 10.09.1020 and below, 10.08.1060 and below, and 10.06.0200 and below. This flaw allows a remote authenticated user with read-only privileges to escalate their access to administrative levels. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to high impact on confidentiality, integrity, and availability. While Aruba has released patches, there is currently no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.06.0000, < 10.06.0210CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.08.0000, < 10.08.1070CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* | ||
>= 10.09.0000, < 10.09.1030CPE matchmatch criteria | cpe:2.3:o:arubanetworks:aos-cx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.