ArubaOS CLI Privilege Escalation via Authenticated Access
CVE-2023-22775 Published on March 1, 2023
Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface
A vulnerability exists which allows an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
Vulnerability Analysis
CVE-2023-22775 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Products Associated with CVE-2023-22775
stack.watch emails you whenever new vulnerabilities are published in Aruba Networks Arubaos or Aruba Networks Sd Wan. Just hit a watch button to start following.
Affected Versions
Hewlett Packard Enterprise (HPE) Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central:- Version ArubaOS 8.6.x.x: 8.6.0.19 and below is affected.
- Version ArubaOS 8.10.x.x: 8.10.0.4 and below is affected.
- Version ArubaOS 10.3.x.x: 10.3.1.0 and below is affected.
- Version SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.