CVE-2023-22771: Arubanetworks Arubaos
Low severity, CVSS 2.4. EPSS: 0.4% chance of exploitation in the next 30 days.
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account
Affected products
- Arubanetworks Arubaos: from 8.6.0.0, up to and including 8.6.0.19; from 8.10.0.0, up to and including 8.10.0.4; from 10.3.0.0, up to and including 10.3.1.0
- Arubanetworks SD-WAN: from 8.7.0.0-2.3.0.0, up to and including 8.7.0.0-2.3.0.8
Published 2023-03-01. Last modified 2026-06-17.