CVE-2022-23677
Published on: Not Yet Published
Last Modified on: 05/25/2022 05:26:00 PM UTC
Certain versions of 2530 from Arubanetworks contain the following vulnerability:
A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.
- CVE-2022-23677 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.1 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 9.3 - HIGH
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
COMPLETE | COMPLETE | COMPLETE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
www.arubanetworks.com text/plain |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Arubanetworks | 2530 | - | All | All | All |
Operating System | Arubanetworks | 2530 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2530 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2530 Firmware | All | All | All | All |
Hardware
| Arubanetworks | 2540 | - | All | All | All |
Operating System | Arubanetworks | 2540 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2540 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2540 Firmware | All | All | All | All |
Hardware
| Arubanetworks | 2615 | - | All | All | All |
Operating System | Arubanetworks | 2615 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2615 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2615 Firmware | All | All | All | All |
Hardware
| Arubanetworks | 2620 | - | All | All | All |
Operating System | Arubanetworks | 2620 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2620 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2620 Firmware | All | All | All | All |
Hardware
| Arubanetworks | 2915 | - | All | All | All |
Operating System | Arubanetworks | 2915 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2915 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2915 Firmware | All | All | All | All |
Hardware
| Arubanetworks | 2920 | - | All | All | All |
Operating System | Arubanetworks | 2920 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2920 Firmware | All | All | All | All |
Operating System | Arubanetworks | 2920 Firmware | All | All | All | All |
Hardware
| Arubanetworks | 2930f | - | All | All | All |
Operating System | Arubanetworks | 2930f Firmware | All | All | All | All |
Operating System | Arubanetworks | 2930f Firmware | All | All | All | All |
Operating System | Arubanetworks | 2930f Firmware | All | All | All | All |
Operating System | Arubanetworks | 2930f Firmware | All | All | All | All |
Operating System | Arubanetworks | 2930f Firmware | All | All | All | All |
Operating System | Arubanetworks | 2930f Firmware | All | All | All | All |
Hardware
| Arubanetworks | 2930m | - | All | All | All |
Operating System | Arubanetworks | 2930m Firmware | All | All | All | All |
Operating System | Arubanetworks | 2930m Firmware | All | All | All | All |
Operating System | Arubanetworks | 2930m Firmware | All | All | All | All |
Hardware
| Arubanetworks | 3810m | - | All | All | All |
Operating System | Arubanetworks | 3810m Firmware | All | All | All | All |
Operating System | Arubanetworks | 3810m Firmware | All | All | All | All |
Operating System | Arubanetworks | 3810m Firmware | All | All | All | All |
Hardware
| Arubanetworks | 5406r | - | All | All | All |
Operating System | Arubanetworks | 5406r Firmware | All | All | All | All |
Operating System | Arubanetworks | 5406r Firmware | All | All | All | All |
Hardware
| Arubanetworks | 5412r | - | All | All | All |
Operating System | Arubanetworks | 5412r Firmware | All | All | All | All |
Operating System | Arubanetworks | 5412r Firmware | All | All | All | All |
Operating System | Arubanetworks | 5412r Firmware | All | All | All | All |
- cpe:2.3:h:arubanetworks:2530:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2540:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2615:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2620:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2915:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2920:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2930f:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:2930m:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:3810m:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:5406r:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:arubanetworks:5412r:-:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Multiple Aruba switches code execution | CVE-2022-23677 - redpacketsecurity.com/multiple-aruba… | 2022-05-05 10:02:02 |
![]() |
CVE-2022-23677 : A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices versio… twitter.com/i/web/status/1… | 2022-05-10 19:05:38 |
![]() |
Severity: ??? | A remote execution of arbitrary code vul... | CVE-2022-23677 | Link for more: alerts.remotelyrmm.com/CVE-2022-23677 | 2022-05-25 18:28:55 |
![]() |
APC UPS's, and Aruba and Avaya switches affected by nanoSSL exploit | 2022-05-04 07:02:45 |
![]() |
CVE-2022-23677 | 2022-05-10 20:38:43 |