A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
| Vendor | Product | Versions |
|---|---|---|
| hpe | arubaos-cx | 10.18.0000, 10.17.0000, 10.16.0000, 10.13.0000, 10.10.0000 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| aruba | arubaos | cert_advisory | 90% |
| hpe | aruba_cx_10000-48y6c_\(s0f98a\) | cve_cpe | 95% |
| hpe | aruba_cx_6000_24g_\(r8n87a\) | cve_cpe | 95% |
| hpe | aruba_cx_6000_48p_\(r8n86b\) | cve_cpe | 95% |
| hpe | aruba_cx_10040_\(s4r58a\) | cve_cpe | 95% |
Loading…