Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-37893

Опубликовано: 07 окт. 2022
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*
Версия от 10.3.0.0 (включая) до 10.3.1.1 (исключая)
cpe:2.3:o:arubanetworks:instant:*:*:*:*:*:*:*:*
Версия от 6.4.0.0 (включая) до 6.4.4.8-4.2.4.21 (исключая)
cpe:2.3:o:arubanetworks:instant:*:*:*:*:*:*:*:*
Версия от 6.5.0.0 (включая) до 6.5.4.24 (исключая)
cpe:2.3:o:arubanetworks:instant:*:*:*:*:*:*:*:*
Версия от 8.6.0.0 (включая) до 8.6.0.19 (исключая)
cpe:2.3:o:arubanetworks:instant:*:*:*:*:*:*:*:*
Версия от 8.7.0.0 (включая) до 8.7.1.10 (исключая)
cpe:2.3:o:arubanetworks:instant:*:*:*:*:*:*:*:*
Версия от 8.10.0.0 (включая) до 8.10.0.2 (исключая)
Конфигурация 2

Одновременно

cpe:2.3:o:siemens:scalance_w1750d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_w1750d:-:*:*:*:*:*:*:*

EPSS

Процентиль: 65%
0.00486
Низкий

7.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

An authenticated command injection vulnerability exists in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on the underlying operating system of Aruba InstantOS 6.4.x: 6.4.4.8-4.2.4.20 and below; Aruba InstantOS 6.5.x: 6.5.4.23 and below; Aruba InstantOS 8.6.x: 8.6.0.18 and below; Aruba InstantOS 8.7.x: 8.7.1.9 and below; Aruba InstantOS 8.10.x: 8.10.0.1 and below; ArubaOS 10.3.x: 10.3.1.0 and below; Aruba has released upgrades for Aruba InstantOS that address this security vulnerability.

EPSS

Процентиль: 65%
0.00486
Низкий

7.8 High

CVSS3

Дефекты

CWE-78