Aruba Networks ArubaOS是美国安移通(Aruba Networks)公司的一套面向Aruba Mobility-Defined Networks(包括移动控制器和移动接入交换机)的操作系统。 Aruba Networks ArubaOS 存在命令注入漏洞,该漏洞源于命令行界面中存在经过身份验证的命令注入,攻击者利用该漏洞可以在底层操作系统上执行任意命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central | - ArubaOS 10.4.x.x: 10.4.0.1 and below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-35971 | 8.8 HIGH | Unauthenticated Stored Cross-Site Scripting (XSS) in ArubaOS Web-based Management Interfac |
| CVE-2023-35973 | 7.2 HIGH | Authenticated Remote Command Execution in the ArubaOS Command Line Interface |
| CVE-2023-35972 | 7.2 HIGH | Authenticated Remote Command Execution in ArubaOS Web-based Management Interface |
| CVE-2023-35977 | 6.5 MEDIUM | Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface |
| CVE-2023-35976 | 6.5 MEDIUM | Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface |
| CVE-2023-35975 | 6.5 MEDIUM | Authenticated Path Traversal in ArubaOS Command Line Interface Allows for Arbitrary File D |
| CVE-2023-35978 | 6.1 MEDIUM | Reflected Cross-Site Scripting (XSS) in ArubaOS Web-based Management Interface |
| CVE-2023-35979 | 5.3 MEDIUM | Unauthenticated Buffer Overflow Vulnerability in ArubaOS Web-Based Management Interface |
No comments yet