9.8
CVE-2023-22752
- EPSS 2.19%
- Published 01.03.2023 08:15:12
- Last modified 11.03.2025 14:15:17
- Source security-alert@hpe.com
- Teams watchlist Login
- Open Login
There are stack-based buffer overflow vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Data is provided by the National Vulnerability Database (NVD)
Arubanetworks ≫ Sd-wan Version >= 8.7.0.0-2.3.0.0 <= 8.7.0.0-2.3.0.8
Arubanetworks ≫ Arubaos Version >= 8.6.0.0 <= 8.6.0.19
Arubanetworks ≫ Arubaos Version >= 8.10.0.0 <= 8.10.0.4
Arubanetworks ≫ Arubaos Version >= 10.3.0.0 <= 10.3.1.0
02.03.2023: CERT.at Warnung
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.19% | 0.829 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
security-alert@hpe.com | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.