CVE-2023-1168: HPE Arubaos-Cx

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system, leading to a complete compromise of the switch running AOS-CX.

Affected products

  • HPE Arubaos-Cx: from 10.06.0000, before 10.06.0240 (fixed in 10.06.0240); from 10.08.0000, up to and including 10.08.1070; from 10.09.0000, up to and including 10.09.1020; from 10.10.0000, before 10.10.1030 (fixed in 10.10.1030)

Published 2023-03-22. Last modified 2026-06-17.