7.2

CVE-2023-45626

An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks ≫ Arubaos Version >= 10.3.0.0 < 10.4.0.3
Arubanetworks ≫ Arubaos Version 10.5.0.0
Hp ≫ Instantos Version >= 6.4.0.0 < 8.6.0.23
Hp ≫ Instantos Version >= 8.10.0.0 < 8.10.0.9
Hp ≫ Instantos Version >= 8.11.0.0 < 8.11.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.94% 0.563
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
HPE 5.5 1.2 4.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-017.txt
Vendor Advisory
Mitigation