Multiple Buffer Overflow Vulnerabilities in BIOS Implementation of 9200 and 9000 Series Controllers and Gateways
CVE-2023-38485

8HIGH

Key Information:

Summary

Vulnerabilities identified in the BIOS of Aruba 9200 and 9000 Series Controllers and Gateways may allow an attacker to execute arbitrary code during the boot sequence. Such exploitation can lead to access and modification of sensitive information within the affected systems, potentially resulting in a complete compromise of the controller's integrity. Organizations using these devices should take immediate action to mitigate the risk.

Affected Version(s)

9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways ArubaOS 10.4.x.x

9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways ArubaOS 10.4.x.x

9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways ArubaOS 8.11.x.x

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nicholas Starke of Aruba Threat Labs
.