CVE-2023-35974
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Jul 5, 2023
Updated: Jul 11, 2023
CWE ID 77
Summary
CVE-2023-35974 refers to authenticated command injection vulnerabilities present in the ArubaOS command line interface. Exploiting these weaknesses allows an attacker to execute arbitrary commands with privileged user access on the underlying operating system. Such exploitation can lead to unauthorized system modifications or data exfiltration. These vulnerabilities pose a serious risk to network security and require immediate patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Arubanetworks Arubaos
Affected Vendors
- Aruba Networks