CVE-2023-22788 — Command Injection in HP Instantos
Severity
8.8HIGHNVD
CNA7.2
EPSS
0.3%
top 47.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 8
Latest updateJul 6
Description
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS 10 command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages3 packages
▶CVEListV5hewlett_packard_enterprise/aruba_access_points_running_instantos_and_arubaos_106 versions+5