Home
HIGH: 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HDefault status
affected
10.17.0000 (semver)
affected
10.16.0000 (semver)
affected
10.13.0000 (semver)
affected
10.10.0000 (semver)
affected
Description
A vulnerability in a custom binary used in AOS-CX Switches' CLI could allow an authenticated remote attacker with high privileges to perform command injection. Successful exploitation could allow an attacker to execute unauthorized commands.
Product status
10.17.0000 (semver)
10.16.0000 (semver)
10.13.0000 (semver)
10.10.0000 (semver)
Credits
This vulnerability was discovered and reported by moonv through HPE Aruba Networking's Bug Bounty program.
References
support.hpe.com/...y?docId=hpesbnw05027en_us&docLocale=en_US