CVE-2022-23677

A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:5406r:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2920:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2930f:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2930m:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2530:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2540:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:5412r:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
OR cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2615:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
OR cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2620:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2915:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
OR cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:3810m:-:*:*:*:*:*:*:*

History

25 May 2022, 17:26

Type Values Removed Values Added
CPE cpe:2.3:h:arubanetworks:3810m:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2915:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2930m:-:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:5412r:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:5406r:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2615:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2540:-:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2930f:-:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2530:-:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2615_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930f_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5406r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5412r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2920:-:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2620:-:*:*:*:*:*:*:*
References (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-008.txt - (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-008.txt - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 9.3
v3 : 8.1
CWE CWE-787

10 May 2022, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-10 19:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-23677

Mitre link : CVE-2022-23677

CVE.ORG link : CVE-2022-23677


JSON object : View

Products Affected

arubanetworks

  • 2620
  • 5406r
  • 5406r_firmware
  • 5412r
  • 2615_firmware
  • 2540
  • 2530
  • 5412r_firmware
  • 2530_firmware
  • 2915
  • 2930f
  • 2930f_firmware
  • 2915_firmware
  • 2930m_firmware
  • 2540_firmware
  • 2930m
  • 2920
  • 2920_firmware
  • 3810m_firmware
  • 3810m
  • 2620_firmware
  • 2615
CWE
CWE-787

Out-of-bounds Write