Vulnerabilities > Arubanetworks > AOS CX > High

DATE CVE VULNERABILITY TITLE RISK
2022-09-06 CVE-2022-23679 Cross-Site Request Forgery (CSRF) vulnerability in Arubanetworks Aos-Cx
AOS-CX lacks Anti-CSRF protections in place for state-changing operations.
network
low complexity
arubanetworks CWE-352
8.8
2022-09-06 CVE-2022-23680 Cross-Site Request Forgery (CSRF) vulnerability in Arubanetworks Aos-Cx
AOS-CX lacks Anti-CSRF protections in place for state-changing operations.
network
low complexity
arubanetworks CWE-352
8.8
2022-09-06 CVE-2022-23681 OS Command Injection vulnerability in Arubanetworks Aos-Cx
Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection.
local
low complexity
arubanetworks CWE-78
7.8
2022-09-06 CVE-2022-23682 OS Command Injection vulnerability in Arubanetworks Aos-Cx
Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection.
local
low complexity
arubanetworks CWE-78
7.8
2022-09-06 CVE-2022-23683 OS Command Injection vulnerability in Arubanetworks Aos-Cx
Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts.
network
low complexity
arubanetworks CWE-78
7.2
2022-09-06 CVE-2022-23684 Unspecified vulnerability in Arubanetworks Aos-Cx
A vulnerability in the web-based management interface of AOS-CX could allow a remote authenticated user with read-only privileges to escalate their permissions to those of an administrative user.
network
low complexity
arubanetworks
8.8