CVE-2023-38485
Last modified
CVE-2023-38485 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to gain access to and change underlying sensitive information in the affected controller leading to complete system compromise.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to gain access to and change underlying sensitive information in the affected controller leading to complete system compromise.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Arubanetworks | Arubaos | >= 8.6.0.0, < 8.6.0.22 |
| Arubanetworks | Arubaos | >= 8.10.0.0, < 8.10.0.7 |
| Arubanetworks | Arubaos | >= 8.11.0.0, < 8.11.1.1 |
| Arubanetworks | Arubaos | >= 10.4.0.0, < 10.4.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-38485?
How severe is CVE-2023-38485?
How do I fix CVE-2023-38485?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-3848A vulnerability, which was classified as problematic, has be…6.1
- CVE-2023-38480Missing Authorization vulnerability in Certain Dev Booster E…5.3
- CVE-2023-38481URL Redirection to Untrusted Site ('Open Redirect') vulnerab…6.1
- CVE-2023-38482Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabili…4.8
- CVE-2023-38483Missing Authorization vulnerability in Dylan Blokhuis Instan…5.4
- CVE-2023-38484Vulnerabilities exist in the BIOS implementation of Aruba 92…6.4
- CVE-2023-38486A vulnerability in the secure boot implementation on affecte…6.4
- CVE-2023-38487HedgeDoc is software for creating real-time collaborative ma…8.2
- CVE-2023-38488Kirby is a content management system. A vulnerability in ver…8.8
- CVE-2023-38489Kirby is a content management system. A vulnerability in ver…7.3
- CVE-2023-3849A vulnerability, which was classified as problematic, was fo…6.1
- CVE-2023-38490Kirby is a content management system. A vulnerability in ver…10
Are you affected by CVE-2023-38485?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
