CVE-2023-38486
Hardware Root of Trust Bypass in 9200 and 9000 Series Controllers and Gateways
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned kernel images from executing. An attacker can use this vulnerability to execute arbitrary runtime operating systems, including unverified and unsigned OS images.
Una vulnerabilidad en la implementación de arranque seguro en los Controladores y Gateways de las Series Aruba 9200 y 9000 afectados permite a un atacante eludir los controles de seguridad que normalmente prohibirían la ejecución de imágenes del kernel sin firmar. Un atacante puede utilizar esta vulnerabilidad para ejecutar sistemas operativos en tiempo de ejecución arbitrarios, incluidas imágenes de sistema operativo no verificadas y sin firmar.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-07-18 CVE Reserved
- 2023-09-06 CVE Published
- 2023-09-07 EPSS Updated
- 2024-09-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-014.txt | 2023-09-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.6.0.0 < 8.6.0.22 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.6.0.0 < 8.6.0.22" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004 Search vendor "Arubanetworks" for product "9004" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.6.0.0 < 8.6.0.22 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.6.0.0 < 8.6.0.22" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004-lte Search vendor "Arubanetworks" for product "9004-lte" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.6.0.0 < 8.6.0.22 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.6.0.0 < 8.6.0.22" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9012 Search vendor "Arubanetworks" for product "9012" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.6.0.0 < 8.6.0.22 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.6.0.0 < 8.6.0.22" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9240 Search vendor "Arubanetworks" for product "9240" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.10.0.0 < 8.10.0.7 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.10.0.0 < 8.10.0.7" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004 Search vendor "Arubanetworks" for product "9004" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.10.0.0 < 8.10.0.7 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.10.0.0 < 8.10.0.7" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004-lte Search vendor "Arubanetworks" for product "9004-lte" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.10.0.0 < 8.10.0.7 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.10.0.0 < 8.10.0.7" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9012 Search vendor "Arubanetworks" for product "9012" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.10.0.0 < 8.10.0.7 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.10.0.0 < 8.10.0.7" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9240 Search vendor "Arubanetworks" for product "9240" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.11.0.0 < 8.11.1.1 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.11.0.0 < 8.11.1.1" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004 Search vendor "Arubanetworks" for product "9004" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.11.0.0 < 8.11.1.1 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.11.0.0 < 8.11.1.1" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004-lte Search vendor "Arubanetworks" for product "9004-lte" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.11.0.0 < 8.11.1.1 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.11.0.0 < 8.11.1.1" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9012 Search vendor "Arubanetworks" for product "9012" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 8.11.0.0 < 8.11.1.1 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 8.11.0.0 < 8.11.1.1" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9240 Search vendor "Arubanetworks" for product "9240" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 10.4.0.0 < 10.4.0.2 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 10.4.0.0 < 10.4.0.2" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004 Search vendor "Arubanetworks" for product "9004" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 10.4.0.0 < 10.4.0.2 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 10.4.0.0 < 10.4.0.2" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9004-lte Search vendor "Arubanetworks" for product "9004-lte" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 10.4.0.0 < 10.4.0.2 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 10.4.0.0 < 10.4.0.2" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9012 Search vendor "Arubanetworks" for product "9012" | - | - |
Safe
|
Arubanetworks Search vendor "Arubanetworks" | Arubaos Search vendor "Arubanetworks" for product "Arubaos" | >= 10.4.0.0 < 10.4.0.2 Search vendor "Arubanetworks" for product "Arubaos" and version " >= 10.4.0.0 < 10.4.0.2" | - |
Affected
| in | Arubanetworks Search vendor "Arubanetworks" | 9240 Search vendor "Arubanetworks" for product "9240" | - | - |
Safe
|