CVE-2022-23677

HIGHCVSS 8.1/10EPSS 19.07%

Last modified

CVE-2022-23677 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.. EPSS estimates a 19.07% chance of exploitation in the next 30 days.

Description

A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
19.07%

97.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Arubanetworks5406r Firmware>= 15.00.0, <= 15.16.0023
Arubanetworks5406r Firmware>= 16.01.0, < 16.02.0034
Arubanetworks5406r Firmware>= 16.03.0, < 16.04.0024
Arubanetworks5406r Firmware>= 16.05.0, < 16.08.0025
Arubanetworks5406r Firmware>= 16.09.0, < 16.09.0020
Arubanetworks5406r Firmware>= 16.10.0, < 16.10.0020
Arubanetworks5406r Firmware>= 16.11.0, < 16.11.0004
Arubanetworks2920 Firmware>= 15.00.0, <= 15.16.0023
Arubanetworks2920 Firmware>= 16.01.0, < 16.02.0034
Arubanetworks2920 Firmware>= 16.03.0, <= 16.04.0024
Arubanetworks2920 Firmware>= 16.05.0, < 16.08.0025
Arubanetworks2920 Firmware>= 16.09.0, < 16.09.0020
Arubanetworks2920 Firmware>= 16.10.0, < 16.10.0020
Arubanetworks2920 Firmware>= 16.11.0, < 16.11.0004
Arubanetworks2930f Firmware>= 15.00.0, <= 15.16.0023
Arubanetworks2930f Firmware>= 16.01.0, < 16.02.0034
Arubanetworks2930f Firmware>= 16.03.0, <= 16.04.0024
Arubanetworks2930f Firmware>= 16.05.0, < 16.08.0025
Arubanetworks2930f Firmware>= 16.09.0, <= 16.09.0020
Arubanetworks2930f Firmware>= 16.10.0, <= 16.10.0020
Arubanetworks2930f Firmware>= 16.11.0, <= 16.11.0004
Arubanetworks2930m Firmware>= 15.00.0, <= 15.16.0023
Arubanetworks2930m Firmware>= 16.01.0, < 16.02.0034
Arubanetworks2930m Firmware>= 16.03.0, <= 16.04.0024
Arubanetworks2930m Firmware>= 16.05.0, < 16.08.0025
Arubanetworks2930m Firmware>= 16.09.0, < 16.09.0020
Arubanetworks2930m Firmware>= 16.10.0, < 16.10.0020
Arubanetworks2930m Firmware>= 16.11.0, < 16.11.0004
Arubanetworks2530 Firmware>= 15.00.0, <= 15.16.0023
Arubanetworks2530 Firmware>= 16.01.0, < 16.02.0034
Arubanetworks2530 Firmware>= 16.03.0, <= 16.04.0024
Arubanetworks2530 Firmware>= 16.05.0, < 16.08.0025
Arubanetworks2530 Firmware>= 16.09.0, < 16.09.0020
Arubanetworks2530 Firmware>= 16.10.0, < 16.10.0020
Arubanetworks2530 Firmware>= 16.11.0, < 16.11.0004
Arubanetworks2540 Firmware>= 15.00.0, <= 15.16.0023
Arubanetworks2540 Firmware>= 16.01.0, < 16.02.0034
Arubanetworks2540 Firmware>= 16.03.0, <= 16.04.0024
Arubanetworks2540 Firmware>= 16.05.0, < 16.08.0025
Arubanetworks2540 Firmware>= 16.09.0, < 16.09.0020
Arubanetworks2540 Firmware>= 16.10.0, < 16.10.0020
Arubanetworks2540 Firmware>= 16.11.0, < 16.11.0004
Arubanetworks5412r Firmware>= 15.00.0, <= 15.16.0023
Arubanetworks5412r Firmware>= 16.01.0, < 16.02.0034
Arubanetworks5412r Firmware>= 16.03.0, <= 16.04.0024
Arubanetworks5412r Firmware>= 16.05.0, < 16.08.0025
Arubanetworks5412r Firmware>= 16.09.0, < 16.09.0020
Arubanetworks5412r Firmware>= 16.10.0, < 16.10.0020
Arubanetworks5412r Firmware>= 16.11.0, < 16.11.0004
Arubanetworks2615 Firmware>= 15.00.0, <= 15.16.0023

Showing 50 of 77 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-23677?
A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.
How severe is CVE-2022-23677?
CVE-2022-23677 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 19.07% probability of exploitation in the next 30 days.
How do I fix CVE-2022-23677?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-23677?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST