« Volver al listado

CVE-2023-38486

Estado: ModificadaMedia (6.4)—

A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned kernel images from executing. An attacker can use this vulnerability to execute arbitrary runtime operating systems, including unverified and unsigned OS images.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-38486",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-38486",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-26T19:38:37.378313Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.7,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise (HPE)",
          "product": "9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways",
          "versions": [
            {
              "status": "affected",
              "version": "ArubaOS 10.4.x.x",
              "versionType": "semver",
              "lessThanOrEqual": "<=10.4.0.1"
            },
            {
              "status": "affected",
              "version": "ArubaOS 8.11.x.x",
              "versionType": "semver",
              "lessThanOrEqual": "<=8.11.1.0"
            },
            {
              "status": "affected",
              "version": "ArubaOS 8.10.x.x",
              "versionType": "semver",
              "lessThanOrEqual": "<=8.10.0.6"
            },
            {
              "status": "affected",
              "version": "ArubaOS 8.6.x.x",
              "versionType": "semver",
              "lessThanOrEqual": "<=8.6.0.21"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*"
          ],
          "vendor": "arubanetworks",
          "product": "arubaos",
          "versions": [
            {
              "status": "affected",
              "version": "8.6.0.0",
              "lessThan": "8.6.0.22",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "8.10.0.0",
              "lessThan": "8.10.0.7",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "8.11.0.0",
              "lessThan": "8.11.1.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "10.4.0.0",
              "lessThan": "10.4.0.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-09-06T18:15:08.547",
  "references": [
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned kernel images from executing. An attacker can use this vulnerability to execute arbitrary runtime operating systems, including unverified and unsigned OS images."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en la implementación de arranque seguro en los Controladores y Gateways de las Series Aruba 9200 y 9000 afectados permite a un atacante eludir los controles de seguridad que normalmente prohibirían la ejecución de imágenes del kernel sin firmar. Un atacante puede utilizar esta vulnerabilidad para ejecutar sistemas operativos en tiempo de ejecución arbitrarios, incluidas imágenes de sistema operativo no verificadas y sin firmar."
    }
  ],
  "lastModified": "2026-06-17T06:10:16.890",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ADB9BE64-9455-46B2-80C8-BD9B88A8F372",
              "versionEndExcluding": "8.6.0.22",
              "versionStartIncluding": "8.6.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48293E3F-C6BD-4875-8C7A-67ED41B7C18D",
              "versionEndExcluding": "8.10.0.7",
              "versionStartIncluding": "8.10.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A22E7E61-B318-47C8-8C72-498A17031997",
              "versionEndExcluding": "8.11.1.1",
              "versionStartIncluding": "8.11.0.0"
            },
            {
              "criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6418722E-304A-46EF-8D9E-EB42596F0DFC",
              "versionEndExcluding": "10.4.0.2",
              "versionStartIncluding": "10.4.0.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arubanetworks:9004:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CFA13FF5-7C60-48B4-AF46-18A9F19D5D42"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:9004-lte:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0B1EB3D9-77B5-4DBE-9518-23DD0DA06BC9"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:9012:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "17162DB3-973E-47C6-9157-39A0E94603F2"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:9240:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A6BF9E0D-630F-40B4-9109-560CA13C981B"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}