CVE-2023-38485
Estado: ModificadaMedia (6.4)—
Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to gain access to and change underlying sensitive information in the affected controller leading to complete system compromise.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-787
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-38485",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-38485",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-30T16:15:14.407752Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-alert@hpe.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 1.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.4,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.5
}
]
},
"affected": [
{
"source": "security-alert@hpe.com",
"affectedData": [
{
"vendor": "Hewlett Packard Enterprise (HPE)",
"product": "9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways",
"versions": [
{
"status": "affected",
"version": "ArubaOS 10.4.x.x",
"versionType": "semver",
"lessThanOrEqual": "<=10.4.0.1"
},
{
"status": "affected",
"version": "ArubaOS 8.11.x.x",
"versionType": "semver",
"lessThanOrEqual": "<=8.11.1.0"
},
{
"status": "affected",
"version": "ArubaOS 8.10.x.x",
"versionType": "semver",
"lessThanOrEqual": "<=8.10.0.6"
},
{
"status": "affected",
"version": "ArubaOS 8.6.x.x",
"versionType": "semver",
"lessThanOrEqual": "<=8.6.0.21"
}
],
"defaultStatus": "affected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:hewlett_packard_enterprise:9200_series_mobility_controllers_and_sd-wan_gateways_9000_series_mobility_controllers_and_sd-wan:*:*:*:*:*:*:*:*"
],
"vendor": "hewlett_packard_enterprise",
"product": "9200_series_mobility_controllers_and_sd-wan_gateways_9000_series_mobility_controllers_and_sd-wan",
"versions": [
{
"status": "affected",
"version": "aruba-os_8.11.x.x",
"versionType": "semver",
"lessThanOrEqual": "8.11.1.0"
},
{
"status": "affected",
"version": "aruba-os_10.4.x.x",
"versionType": "semver",
"lessThanOrEqual": "10.4.0.1"
},
{
"status": "affected",
"version": "aruba-os_8.10.x.x",
"versionType": "semver",
"lessThanOrEqual": "8.10.0.6"
},
{
"status": "affected",
"version": "aruba-os_8.11.x.x",
"versionType": "semver",
"lessThanOrEqual": "8.6.0.21"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2023-09-06T18:15:08.480",
"references": [
{
"url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt",
"tags": [
"Vendor Advisory"
],
"source": "security-alert@hpe.com"
},
{
"url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to gain access to and change underlying sensitive information in the affected controller leading to complete system compromise."
},
{
"lang": "es",
"value": "Existen vulnerabilidades en la implementación del BIOS de los Controladores y Gateways de las Series 9200 y 9000 de Aruba que podrían permitir a un atacante ejecutar código arbitrario en las primeras etapas de la secuencia de inicio. Un atacante podría aprovechar esta vulnerabilidad para obtener acceso y cambiar información sensible subyacente en el controlador afectado, lo que comprometería completamente el sistema."
}
],
"lastModified": "2026-06-17T06:10:16.693",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADB9BE64-9455-46B2-80C8-BD9B88A8F372",
"versionEndExcluding": "8.6.0.22",
"versionStartIncluding": "8.6.0.0"
},
{
"criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "48293E3F-C6BD-4875-8C7A-67ED41B7C18D",
"versionEndExcluding": "8.10.0.7",
"versionStartIncluding": "8.10.0.0"
},
{
"criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A22E7E61-B318-47C8-8C72-498A17031997",
"versionEndExcluding": "8.11.1.1",
"versionStartIncluding": "8.11.0.0"
},
{
"criteria": "cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6418722E-304A-46EF-8D9E-EB42596F0DFC",
"versionEndExcluding": "10.4.0.2",
"versionStartIncluding": "10.4.0.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:arubanetworks:9004:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CFA13FF5-7C60-48B4-AF46-18A9F19D5D42"
},
{
"criteria": "cpe:2.3:h:arubanetworks:9004-lte:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0B1EB3D9-77B5-4DBE-9518-23DD0DA06BC9"
},
{
"criteria": "cpe:2.3:h:arubanetworks:9012:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "17162DB3-973E-47C6-9157-39A0E94603F2"
},
{
"criteria": "cpe:2.3:h:arubanetworks:9240:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A6BF9E0D-630F-40B4-9109-560CA13C981B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "security-alert@hpe.com"
}