9.3

CVE-2022-23677

A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.

Data is provided by the National Vulnerability Database (NVD)
Arubanetworks5406r Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks5406r Version-
Arubanetworks5406r Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks5406r Version-
Arubanetworks5406r Firmware Version >= 16.03.0 < 16.04.0024
   Arubanetworks5406r Version-
Arubanetworks5406r Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks5406r Version-
Arubanetworks5406r Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks5406r Version-
Arubanetworks5406r Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks5406r Version-
Arubanetworks5406r Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks5406r Version-
Arubanetworks2920 Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks2920 Version-
Arubanetworks2930f Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2930f Version-
Arubanetworks2930f Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2930f Version-
Arubanetworks2930f Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2930f Version-
Arubanetworks2930f Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2930f Version-
Arubanetworks2930f Firmware Version >= 16.09.0 <= 16.09.0020
   Arubanetworks2930f Version-
Arubanetworks2930f Firmware Version >= 16.10.0 <= 16.10.0020
   Arubanetworks2930f Version-
Arubanetworks2930f Firmware Version >= 16.11.0 <= 16.11.0004
   Arubanetworks2930f Version-
Arubanetworks2930m Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2930m Version-
Arubanetworks2930m Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2930m Version-
Arubanetworks2930m Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2930m Version-
Arubanetworks2930m Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2930m Version-
Arubanetworks2930m Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks2930m Version-
Arubanetworks2930m Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks2930m Version-
Arubanetworks2930m Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks2930m Version-
Arubanetworks2530 Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2530 Version-
Arubanetworks2530 Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2530 Version-
Arubanetworks2530 Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2530 Version-
Arubanetworks2530 Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2530 Version-
Arubanetworks2530 Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks2530 Version-
Arubanetworks2530 Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks2530 Version-
Arubanetworks2530 Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks2530 Version-
Arubanetworks2540 Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks2540 Version-
Arubanetworks5412r Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks5412r Version-
Arubanetworks5412r Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks5412r Version-
Arubanetworks5412r Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks5412r Version-
Arubanetworks5412r Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks5412r Version-
Arubanetworks5412r Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks5412r Version-
Arubanetworks5412r Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks5412r Version-
Arubanetworks5412r Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks5412r Version-
Arubanetworks2615 Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2615 Version-
Arubanetworks2615 Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2615 Version-
Arubanetworks2615 Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2615 Version-
Arubanetworks2615 Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2615 Version-
Arubanetworks2615 Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks2615 Version-
Arubanetworks2615 Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks2615 Version-
Arubanetworks2615 Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks2615 Version-
Arubanetworks2620 Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2620 Version-
Arubanetworks2620 Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2620 Version-
Arubanetworks2620 Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2620 Version-
Arubanetworks2620 Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2620 Version-
Arubanetworks2620 Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks2620 Version-
Arubanetworks2620 Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks2620 Version-
Arubanetworks2620 Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks2620 Version-
Arubanetworks2915 Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks2915 Version-
Arubanetworks2915 Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks2915 Version-
Arubanetworks2915 Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks2915 Version-
Arubanetworks2915 Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks2915 Version-
Arubanetworks2915 Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks2915 Version-
Arubanetworks2915 Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks2915 Version-
Arubanetworks2915 Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks2915 Version-
Arubanetworks3810m Firmware Version >= 15.00.0 <= 15.16.0023
   Arubanetworks3810m Version-
Arubanetworks3810m Firmware Version >= 16.01.0 < 16.02.0034
   Arubanetworks3810m Version-
Arubanetworks3810m Firmware Version >= 16.03.0 <= 16.04.0024
   Arubanetworks3810m Version-
Arubanetworks3810m Firmware Version >= 16.05.0 < 16.08.0025
   Arubanetworks3810m Version-
Arubanetworks3810m Firmware Version >= 16.09.0 < 16.09.0020
   Arubanetworks3810m Version-
Arubanetworks3810m Firmware Version >= 16.10.0 < 16.10.0020
   Arubanetworks3810m Version-
Arubanetworks3810m Firmware Version >= 16.11.0 < 16.11.0004
   Arubanetworks3810m Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.49% 0.907
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.