An authenticated remote code execution vulnerability
exists in the AOS-CX Network Analytics Engine. Successful
exploitation of this vulnerability results in the ability to
execute arbitrary code as a privileged user on the underlying
operating system, leading to a complete compromise of the
switch running AOS-CX.


Project Subscriptions

Vendors Products
Aruba Cx 10000-48y6 Subscribe
Aruba Cx 6200f 48g Subscribe
Aruba Cx 6200m 24g Subscribe
Aruba Cx 6300m 24p Subscribe
Aruba Cx 6300m 48g Subscribe
Aruba Cx 6405 Subscribe
Aruba Cx 6410 Subscribe
Aruba Cx 8320-32 Subscribe
Aruba Cx 8320-48p Subscribe
Aruba Cx 8325-32c Subscribe
Aruba Cx 8325-48y8c Subscribe
Aruba Cx 8360-12c Subscribe
Aruba Cx 8360-16y2c Subscribe
Aruba Cx 8360-24xf2c Subscribe
Aruba Cx 8360-32y4c Subscribe
Aruba Cx 8360-48xt4c Subscribe
Aruba Cx 8360-48y6c Subscribe
Aruba Cx 8400 Subscribe
Aruba Cx 9300 32d Subscribe
Arubaos-cx Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-23450 An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2025-02-26T16:33:03.782Z

Reserved: 2023-03-03T16:58:46.073Z

Link: CVE-2023-1168

cve-icon Vulnrichment

Updated: 2024-08-02T05:40:57.963Z

cve-icon NVD

Status : Modified

Published: 2023-03-22T06:15:09.390

Modified: 2025-02-26T17:15:14.790

Link: CVE-2023-1168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses