Aller au contenu

Fiche vulnérabilité

CVE-2023-22758 : faille élevée arubanetworks sd-wan (CVSS 7.2)

Description

Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. This allows an attacker to fully compromise the underlying operating system on the device running ArubaOS.

En bref

Sévérité
Élevée (CVSS 7.2)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
1 mars 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • arubanetworks sd-wan
  • arubanetworks arubaos

Références

Rechercher une autre vulnérabilité dans la base CVE