CVE-2022-23676

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
10/05/2022
Last modified:
25/05/2022

Description

A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:* 15.00.0 (including) 15.16.0023 (including)
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:* 16.01.0 (including) 16.02.0034 (excluding)
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:* 16.03.0 (including) 16.04.0024 (excluding)
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:* 16.05.0 (including) 16.08.0025 (excluding)
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:* 16.09.0 (including) 16.09.0020 (excluding)
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:* 16.10.0 (including) 16.10.0020 (excluding)
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:* 16.11.0 (including) 16.11.0004 (excluding)
cpe:2.3:h:arubanetworks:5406r:-:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:* 15.00.0 (including) 15.16.0023 (including)
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:* 16.01.0 (including) 16.02.0034 (excluding)
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:* 16.03.0 (including) 16.04.0024 (including)
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:* 16.05.0 (including) 16.08.0025 (excluding)
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:* 16.09.0 (including) 16.09.0020 (excluding)
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:* 16.10.0 (including) 16.10.0020 (excluding)
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:* 16.11.0 (including) 16.11.0004 (excluding)


References to Advisories, Solutions, and Tools