CVE-2022-23676
Last modified
CVE-2022-23676 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.. EPSS estimates a 21.36% chance of exploitation in the next 30 days.
Description
A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | 5406r Firmware | >= 15.00.0, <= 15.16.0023 |
| Arubanetworks | 5406r Firmware | >= 16.01.0, < 16.02.0034 |
| Arubanetworks | 5406r Firmware | >= 16.03.0, < 16.04.0024 |
| Arubanetworks | 5406r Firmware | >= 16.05.0, < 16.08.0025 |
| Arubanetworks | 5406r Firmware | >= 16.09.0, < 16.09.0020 |
| Arubanetworks | 5406r Firmware | >= 16.10.0, < 16.10.0020 |
| Arubanetworks | 5406r Firmware | >= 16.11.0, < 16.11.0004 |
| Arubanetworks | 3810m Firmware | >= 15.00.0, <= 15.16.0023 |
| Arubanetworks | 3810m Firmware | >= 16.01.0, < 16.02.0034 |
| Arubanetworks | 3810m Firmware | >= 16.03.0, <= 16.04.0024 |
| Arubanetworks | 3810m Firmware | >= 16.05.0, < 16.08.0025 |
| Arubanetworks | 3810m Firmware | >= 16.09.0, < 16.09.0020 |
| Arubanetworks | 3810m Firmware | >= 16.10.0, < 16.10.0020 |
| Arubanetworks | 3810m Firmware | >= 16.11.0, < 16.11.0004 |
| Arubanetworks | 2920 Firmware | >= 15.00.0, <= 15.16.0023 |
| Arubanetworks | 2920 Firmware | >= 16.01.0, < 16.02.0034 |
| Arubanetworks | 2920 Firmware | >= 16.03.0, <= 16.04.0024 |
| Arubanetworks | 2920 Firmware | >= 16.05.0, < 16.08.0025 |
| Arubanetworks | 2920 Firmware | >= 16.09.0, < 16.09.0020 |
| Arubanetworks | 2920 Firmware | >= 16.10.0, < 16.10.0020 |
| Arubanetworks | 2920 Firmware | >= 16.11.0, < 16.11.0004 |
| Arubanetworks | 2930f Firmware | >= 15.00.0, <= 15.16.0023 |
| Arubanetworks | 2930f Firmware | >= 16.01.0, < 16.02.0034 |
| Arubanetworks | 2930f Firmware | >= 16.03.0, <= 16.04.0024 |
| Arubanetworks | 2930f Firmware | >= 16.05.0, < 16.08.0025 |
| Arubanetworks | 2930f Firmware | >= 16.09.0, <= 16.09.0020 |
| Arubanetworks | 2930f Firmware | >= 16.10.0, <= 16.10.0020 |
| Arubanetworks | 2930f Firmware | >= 16.11.0, <= 16.11.0004 |
| Arubanetworks | 2930m Firmware | >= 15.00.0, <= 15.16.0023 |
| Arubanetworks | 2930m Firmware | >= 16.01.0, < 16.02.0034 |
| Arubanetworks | 2930m Firmware | >= 16.03.0, <= 16.04.0024 |
| Arubanetworks | 2930m Firmware | >= 16.05.0, < 16.08.0025 |
| Arubanetworks | 2930m Firmware | >= 16.09.0, < 16.09.0020 |
| Arubanetworks | 2930m Firmware | >= 16.10.0, < 16.10.0020 |
| Arubanetworks | 2930m Firmware | >= 16.11.0, < 16.11.0004 |
| Arubanetworks | 2530 Firmware | >= 15.00.0, <= 15.16.0023 |
| Arubanetworks | 2530 Firmware | >= 16.01.0, < 16.02.0034 |
| Arubanetworks | 2530 Firmware | >= 16.03.0, <= 16.04.0024 |
| Arubanetworks | 2530 Firmware | >= 16.05.0, < 16.08.0025 |
| Arubanetworks | 2530 Firmware | >= 16.09.0, < 16.09.0020 |
| Arubanetworks | 2530 Firmware | >= 16.10.0, < 16.10.0020 |
| Arubanetworks | 2530 Firmware | >= 16.11.0, < 16.11.0004 |
| Arubanetworks | 2540 Firmware | >= 15.00.0, <= 15.16.0023 |
| Arubanetworks | 2540 Firmware | >= 16.01.0, < 16.02.0034 |
| Arubanetworks | 2540 Firmware | >= 16.03.0, <= 16.04.0024 |
| Arubanetworks | 2540 Firmware | >= 16.05.0, < 16.08.0025 |
| Arubanetworks | 2540 Firmware | >= 16.09.0, < 16.09.0020 |
| Arubanetworks | 2540 Firmware | >= 16.10.0, < 16.10.0020 |
| Arubanetworks | 2540 Firmware | >= 16.11.0, < 16.11.0004 |
| Arubanetworks | 5412r Firmware | >= 15.00.0, <= 15.16.0023 |
Showing 50 of 77 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-23676?
How severe is CVE-2022-23676?
How do I fix CVE-2022-23676?
Are you affected by CVE-2022-23676?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
