CVE-2023-38485

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Sep 6, 2023
Updated: Sep 15, 2023
CWE ID 787

Summary

CVE-2023-38485 is a critical vulnerability affecting the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways. This issue allows an attacker to execute arbitrary code during the early stages of the boot sequence. By exploiting this vulnerability, an attacker can gain unauthorized access to and manipulate sensitive information in the affected controller, potentially resulting in a complete system compromise. This vulnerability poses a significant threat to organizational networks and requires immediate attention and patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Arubanetworks Arubaos

Affected Vendors

  • Aruba Networks