Description
An authenticated remote code execution vulnerability
exists in the AOS-CX Network Analytics Engine. Successful
exploitation of this vulnerability results in the ability to
execute arbitrary code as a privileged user on the underlying
operating system, leading to a complete compromise of the
switch running AOS-CX.


Published: 2023-03-21
Score: 7.2 High
EPSS: 1.7% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-23450 An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Subscriptions

Hpe Aruba Cx 10000-48y6 Aruba Cx 6200f 48g Aruba Cx 6200m 24g Aruba Cx 6300m 24p Aruba Cx 6300m 48g Aruba Cx 6405 Aruba Cx 6410 Aruba Cx 8320-32 Aruba Cx 8320-48p Aruba Cx 8325-32c Aruba Cx 8325-48y8c Aruba Cx 8360-12c Aruba Cx 8360-16y2c Aruba Cx 8360-24xf2c Aruba Cx 8360-32y4c Aruba Cx 8360-48xt4c Aruba Cx 8360-48y6c Aruba Cx 8400 Aruba Cx 9300 32d Arubaos-cx
cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-02-26T16:33:03.782Z

Reserved: 2023-03-03T16:58:46.073Z

Link: CVE-2023-1168

cve-icon Vulnrichment

Updated: 2024-08-02T05:40:57.963Z

cve-icon NVD

Status : Modified

Published: 2023-03-22T06:15:09.390

Modified: 2025-02-26T17:15:14.790

Link: CVE-2023-1168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses