PT-2022-16196 · Aruba · Arubaos-Cx Switches

Published

2022-09-06

·

Updated

2023-08-08

·

CVE-2022-23686

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions ArubaOS-CX Switches versions 10.09.1010 and below ArubaOS-CX Switches versions 10.08.1050 and below ArubaOS-CX Switches versions 10.06.0190 and below
Description Multiple vulnerabilities exist in the processing of packet data by the LLDP service of AOS-CX. Successful exploitation of these vulnerabilities may allow an attacker to impact the availability of the AOS-CX LLDP service and/or the management plane of the switch.
Recommendations For versions 10.09.1010 and below, upgrade to a version above 10.09.1010. For versions 10.08.1050 and below, upgrade to a version above 10.08.1050. For versions 10.06.0190 and below, upgrade to a version above 10.06.0190.

Fix

Related Identifiers

CVE-2022-23686

Affected Products

Arubaos-Cx Switches