« Volver al listado

CVE-2023-39267

Estado: ModificadaMedia (6.5)—

An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Denial-of-Service (DoS) condition in the switch.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-39267",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-39267",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-27T19:41:36.720364Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-alert@hpe.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@hpe.com",
      "affectedData": [
        {
          "vendor": "Hewlett Packard Enterprise",
          "product": "ArubaOS-Switch",
          "versions": [
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.11.xxxx: KB/WC/YA/YB/YC.16.11.0012 and below."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.10.xxxx: KB/WC/YA/YB/YC.16.10.0025 and below."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.10.xxxx: WB.16.10.23 and below."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.09.xxxx: All versions."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0026 and below."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.07.xxxx: All versions."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.06.xxxx: All versions."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.05.xxxx: All versions."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.04.xxxx: KA/RA.16.04.0026 and below."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.03.xxxx: All versions."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.02.xxxx: All versions."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 16.01.xxxx: All versions."
            },
            {
              "status": "affected",
              "version": "ArubaOS-Switch 15.xx.xxxx: 15.16.0025 and below."
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2023-08-29T20:15:09.743",
  "references": [
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-013.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-alert@hpe.com"
    },
    {
      "url": "https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-013.txt",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An authenticated remote code execution vulnerability exists in the command line interface in ArubaOS-Switch. Successful exploitation results in a Denial-of-Service (DoS) condition in the switch.\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de ejecución remota de código autenticada en la interfaz de línea de comandos de ArubaOS-Switch. La explotación exitosa da como resultado una condición de denegación de servicio (DoS) en el switch.\n"
    }
  ],
  "lastModified": "2026-06-17T06:11:52.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6EF6288C-3E1F-4E2F-BDE2-319E6774F1BD",
              "versionEndExcluding": "a.15.16.0026"
            },
            {
              "criteria": "cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D421C423-B11A-43F0-A0E9-9ABD0CC3E7A9",
              "versionEndExcluding": "16.04.0027",
              "versionStartIncluding": "16.01.0000"
            },
            {
              "criteria": "cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90E95208-9E6A-4A27-91EF-EFF9EBB5CDF0",
              "versionEndExcluding": "16.08.0027",
              "versionStartIncluding": "16.05.0000"
            },
            {
              "criteria": "cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3A977A83-A7F4-4FE7-9AC9-5584801CC039",
              "versionEndExcluding": "16.10.0024",
              "versionStartIncluding": "16.10.0001"
            },
            {
              "criteria": "cpe:2.3:o:hpe:arubaos-switch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF10EBA8-E257-4E81-8B5A-04E643FD27F4",
              "versionEndExcluding": "16.11.0013",
              "versionStartIncluding": "16.11.0001"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_2530:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "CA0DC0DE-5F4A-4D2A-AFCA-E36A103D5A6E"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_2530ya:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B8251986-B9F2-4345-A4D7-EB3737F12AE0"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_2530yb:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "3D7A8F42-55C8-4A2B-8A34-1B1B8BE3BEDF"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_2540:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "FDEDD15E-289E-4B15-8620-547EA19CAEE7"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_2920:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B1782D4A-AD68-4BD2-8453-EE22BCF2DC99"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_2930f:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "97C4FCD2-BB70-4848-B08A-223B5C3467BB"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_2930m:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2561E158-FB61-4FFD-B680-DADF7BC2C6D1"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_3810m:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F3CE933B-68BA-45BA-81BD-95D873B858B1"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_5406r_zl2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8E982204-9ADC-4242-86C2-A407D6EA7DB0"
            },
            {
              "criteria": "cpe:2.3:h:arubanetworks:aruba_5412r_zl2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8549CD94-50E2-4615-94C2-D76FADFBA3AC"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security-alert@hpe.com"
}