CVE-2023-39268

A memory corruption vulnerability in ArubaOS-Switch could lead to unauthenticated remote code execution by receiving specially crafted packets. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*
OR cpe:2.3:h:arubanetworks:aruba_2530:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2530ya:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2530yb:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2540:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2920:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2930f:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2930m:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_3810m:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_5406r_zl2:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_5412r_zl2:-:*:*:*:*:*:*:*

History

11 Sep 2023, 13:59

Type Values Removed Values Added
First Time Arubanetworks aruba 5406r Zl2
Hpe
Arubanetworks aruba 2540
Arubanetworks
Arubanetworks aruba 5412r Zl2
Arubanetworks aruba 2930f
Arubanetworks aruba 2530yb
Arubanetworks aruba 3810m
Arubanetworks aruba 2930m
Arubanetworks aruba 2920
Hpe arubaos-switch
Arubanetworks aruba 2530ya
Arubanetworks aruba 2530
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2530:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2540:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2930m:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2530yb:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_5412r_zl2:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2530ya:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2930f:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_3810m:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_2920:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:aruba_5406r_zl2:-:*:*:*:*:*:*:*
CWE CWE-787
References (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-013.txt - (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-013.txt - Vendor Advisory

29 Aug 2023, 20:41

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-29 20:15

Updated : 2024-02-28 20:33


NVD link : CVE-2023-39268

Mitre link : CVE-2023-39268

CVE.ORG link : CVE-2023-39268


JSON object : View

Products Affected

arubanetworks

  • aruba_3810m
  • aruba_5412r_zl2
  • aruba_2930m
  • aruba_5406r_zl2
  • aruba_2920
  • aruba_2930f
  • aruba_2540
  • aruba_2530ya
  • aruba_2530
  • aruba_2530yb

hpe

  • arubaos-switch
CWE
CWE-787

Out-of-bounds Write