CVE-2022-23682
- EPSS 0.23%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:05
Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to c...
CVE-2022-23683
- EPSS 1.68%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:05
Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying ...
CVE-2022-23684
- EPSS 0.4%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:05
A vulnerability in the web-based management interface of AOS-CX could allow a remote authenticated user with read-only privileges to escalate their permissions to those of an administrative user. Successful exploitation of this vulnerability allows a...
CVE-2022-23686
- EPSS 0.1%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:06
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of...
CVE-2022-23687
- EPSS 0.1%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:06
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of...
CVE-2022-23688
- EPSS 0.1%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:06
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of...
CVE-2022-23689
- EPSS 0.1%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 17.06.2025 20:15:25
Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of...
CVE-2022-23690
- EPSS 0.39%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:06
A vulnerability in the web-based management interface of AOS-CX could allow a remote unauthenticated attacker to fingerprint the exact version AOS-CX running on the switch. This allows an attacker to retrieve information which could be used to more p...
CVE-2022-23691
- EPSS 0.13%
- Veröffentlicht 06.09.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:49:06
A vulnerability exists in certain AOS-CX switch models which could allow an attacker with access to the recovery console to bypass normal authentication. A successful exploit allows an attacker to bypass system authentication and achieve total switch...
CVE-2022-23679
- EPSS 0.14%
- Veröffentlicht 06.09.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:04
AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attacker to execute commands in the context of another user in ArubaOS-CX Switches version(s): AOS-CX 10.10.xxxx: 10.10.0002 and below,...