CVE-2023-38485
Published: Sep 6, 2023
Modified: Sep 30, 2024
CVSS v3.1
8.0
Description
Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to gain access to and change underlying sensitive information in the affected controller leading to complete system compromise.
| Vendor | Product | Versions |
|---|---|---|
Hewlett Packard Enterprise (HPE) | 9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways | affected ArubaOS 10.4.x.x - <= <=10.4.0.1affected ArubaOS 8.11.x.x - <= <=8.11.1.0affected ArubaOS 8.10.x.x - <= <=8.10.0.6affected ArubaOS 8.6.x.x - <= <=8.6.0.21 |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now