CVE-2023-1168
Estado: ModificadaAlta (8.8)—
Detalles técnicos trazas, registros y código del informe original
An authenticated remote code execution vulnerability
exists in the AOS-CX Network Analytics Engine. Successful
exploitation of this vulnerability results in the ability to
execute arbitrary code as a privileged user on the underlying
operating system, leading to a complete compromise of the
switch running AOS-CX.CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.14%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
- CWE-77
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-1168",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-1168",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-02-26T16:29:51.845138Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-alert@hpe.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-alert@hpe.com",
"affectedData": [
{
"vendor": "Hewlett Packard Enterprise (HPE)",
"product": "Aruba CX 10000 Switch Series, Aruba CX 9300 Switch Series, Aruba CX 8400 Switch Series, Aruba CX 8360 Switch Series, Aruba CX 8325 Switch Series, Aruba CX 8320 Switch Series, Aruba CX 6400 Switch Series, Aruba CX 6300 Switch Series, Aruba CX 6200F Switch Series",
"versions": [
{
"status": "affected",
"version": "AOS-CX 10.10.xxxx: 10.10.1020 and below."
},
{
"status": "affected",
"version": "AOS-CX 10.09.xxxx: 10.09.1020 and below."
},
{
"status": "affected",
"version": "AOS-CX 10.08.xxxx: 10.08.1070 and below."
},
{
"status": "affected",
"version": "AOS-CX 10.06.xxxx: 10.06.0230 and below."
}
],
"platforms": [
"AOS-CX"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-03-22T06:15:09.390",
"references": [
{
"url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-004.txt",
"tags": [
"Vendor Advisory"
],
"source": "security-alert@hpe.com"
},
{
"url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-004.txt",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-77"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An authenticated remote code execution vulnerability\n exists in the AOS-CX Network Analytics Engine. Successful\n exploitation of this vulnerability results in the ability to\n execute arbitrary code as a privileged user on the underlying\n operating system, leading to a complete compromise of the\n switch running AOS-CX.\n\n\n"
}
],
"lastModified": "2026-06-17T05:27:16.293",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93B17071-FD9B-49C1-8C0B-FDA68664E773",
"versionEndExcluding": "10.06.0240",
"versionStartIncluding": "10.06.0000"
},
{
"criteria": "cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C8A631C-CB1E-4314-943D-713DC9EA260E",
"versionEndIncluding": "10.08.1070",
"versionStartIncluding": "10.08.0000"
},
{
"criteria": "cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "936EB0DA-9A69-4E7B-B5F5-437A86B8C897",
"versionEndIncluding": "10.09.1020",
"versionStartIncluding": "10.09.0000"
},
{
"criteria": "cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "690D819F-1B6E-48A1-BEDD-90B511048317",
"versionEndExcluding": "10.10.1030",
"versionStartIncluding": "10.10.0000"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_10000-48y6:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D10D4824-3D75-4CD2-A541-D910B91FD560"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_6200f_48g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F9BC4F4F-5DF6-45D6-9039-BF06C5D53487"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_6200m_24g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D05337A1-9022-41DA-AFED-AE76FC39D3C6"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_6300m_24p:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5172FB6C-C38E-4A5A-8C67-55B475C96B0A"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_6300m_48g:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3FF6C6CE-E842-420D-9C4C-54D4B4F85D14"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_6405:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D118A9A6-BBA4-4149-AE0D-1DA2EB45B53F"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_6410:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "790C5E7A-3405-4873-83E8-4D9C0FEC5E6D"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8320-32:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "873275E0-0BF3-42A6-A88A-4A4CDCC98C37"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8320-48p:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "65875CB1-A9A3-42CC-A14D-7AB4E985808A"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8325-32c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "59B7E2D3-0B72-4A78-AEFA-F106FAD38156"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8325-48y8c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7E87A92B-4EE5-4235-A0DA-195F27841DBB"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8360-12c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6BC24E52-13C0-402F-9ABF-A1DE51719AEF"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8360-16y2c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "76EF979E-061A-42A3-B161-B835E92ED180"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8360-24xf2c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DE04919C-9289-4FB3-938F-F8BB15EC6A74"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8360-32y4c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B630C64B-C474-477D-A80B-A0FB73ACCC49"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8360-48xt4c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "53ABE8B8-A4F6-400B-A893-314BE24D06B8"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8360-48y6c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C44383CC-3751-455E-B1AB-39B16F40DC76"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_8400:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B25A9CD2-5E5F-4BDB-8707-5D6941411A2B"
},
{
"criteria": "cpe:2.3:h:hpe:aruba_cx_9300_32d:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6C595A15-BD04-45A3-A719-3DFB8DAB46E7"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security-alert@hpe.com"
}