Описание
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
Ссылки
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 10.10.1170 (включая)Версия от 10.13.0000 (включая) до 10.13.1160 (включая)Версия от 10.16.0000 (включая) до 10.16.1020 (включая)Версия от 10.17.0000 (включая) до 10.17.0001 (включая)
Одновременно
Одно из
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*
Одно из
cpe:2.3:h:hpe:aruba_cx_10000-48y6c_\(r8p13a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_10000-48y6c_\(r8p14a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_10000-48y6c_\(s0f98a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_10040_\(s4r58a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_10040_32p_\(s4r54a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_10040_32p_\(s4r55a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_10040_32p_\(s4r56a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_4100i_12-port_\(jl817a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_4100i_24-port_\(jl818a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_12g_\(r8n89a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_12p_\(r8n89b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_12p_\(s4r21a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_24g_\(r8n87a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_24g_\(r8n88a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_24p_\(r8n87b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_24p_\(r8n88b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_24p_\(s4r26a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_24p_\(s4r27a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48g_\(r8n85a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48g_\(r8n86a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48g_\(r9y03a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48p_\(r8n85b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48p_\(r8n86b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48p_\(r9y03b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48p_\(s4r20a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48p_\(s4r24a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_48p_\(s4r25a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_8p_\(s4r22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_8p_\(s4r23a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_8p_\(s4r28a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6000_8p_\(s4r29a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6100_12g_\(jl679a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6100_24g_\(jl677a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6100_24g_\(jl678a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6100_48g_\(jl675a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6100_48g_\(jl676a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6100_48g_\(r9y04a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_12g_\(r8q72a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_12g_\(r8v13a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(jl724b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(jl725b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(s0g13a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(s0g14a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(s0m81a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(s0m82a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(s0m86a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_24g_\(s0m87a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(jl726b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(jl727b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(jl728b\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0g15a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0g16a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0g17a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0m83a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0m84a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0m85a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0m88a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0m89a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200f_48g_\(s0m90a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_24g_\(r8q67a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_24g_\(r8q68a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_24g_\(r8v08a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_24g_\(r8v09a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_36g_\(r8q71a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_36g_\(r8v12a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_48g_\(r8q69a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_48g_\(r8q70a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_48g_\(r8v10a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6200m_48g_\(r8v11a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_24_\(jl666a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_24_\(jl668a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_24p_\(s0g96a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_24p_\(s0g98a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_48_\(jl665a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_48_\(jl667a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_48p_\(s0g95a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300f_48p_\(s0g97a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_16p_\(s4p41a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_16p_\(s4p45a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24_\(jl658a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24_\(jl660a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24_\(jl662a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24_\(jl664a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(r8s89a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(r8s92a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(s0f99a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(s0g01a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(s0g03a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(s0g05a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(s4p44a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(s4p48a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_24p_\(s5z46a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_32p_\(s4p42a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_32p_\(s4p46a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48_\(jl659a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48_\(jl661a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48_\(jl663a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48_\(jl762a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(r8s90a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(s0g00a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(s0g02a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(s0g04a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(s0g06a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(s0x44a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(s4p43a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48p_\(s4p47a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6300m_48sr5_\(r8s91a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6405_\(r0x26a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6405_48sfp\+8sfp56_\(r0x30a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6405_96g_\(r0x29a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6405_v2_\(r0x26c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6410_\(r0x27a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6410_96g_\(jl741a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_6410_v2_\(r0x27c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8320_32_\(jl579a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8320_48_\(jl479a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8320_48_\(jl581a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325-32c_\(jl626a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325-32c_\(jl627a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325-48y8c_\(jl624a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325-48y8c_\(jl625a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325-48y8c_\(jl858a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325h-16c_\(s4b22a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325h-16c_\(s4b24a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325h-18y4c_\(s4b21a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325h-18y4c_\(s4b23a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325p-32c_\(s0g07a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8325p-32c_\(s0g08a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-12c_\(jl708c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-12c_\(jl709c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-16y2c_\(jl702c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-16y2c_\(jl703c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-24xf2c_\(jl710c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-24xf2c_\(jl711c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-32y4c_\(jl700c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-32y4c_\(jl701c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-48xt4c_\(jl706c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-48xt4c_\(jl707c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-48y6c_\(jl704c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8360-48y6c_\(jl705c\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8400_\(jl376a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_8400_8-slot_chassis_\(jl375a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r8z97a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r8z98a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r8z99a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_\(r9a00a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_32d_\(r8z96a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_32d_\(r9a29a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300_32d_\(r9a30a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f81a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f82a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f83a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f84a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f87a\):-:*:*:*:*:*:*:*
cpe:2.3:h:hpe:aruba_cx_9300s_32p_\(s0f88a\):-:*:*:*:*:*:*:*
EPSS
Процентиль: 58%
0.00938
Низкий
7.2 High
CVSS3
Дефекты
CWE-77
Связанные уязвимости
CVSS3: 7.2
github
6 месяцев назад
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
EPSS
Процентиль: 58%
0.00938
Низкий
7.2 High
CVSS3
Дефекты
CWE-77