CVE-2023-45626: Arubanetworks Arubaos
High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.
An authenticated vulnerability has been identified allowing an attacker to effectively establish highly privileged persistent arbitrary code execution across boot cycles.
Affected products
- Arubanetworks Arubaos: from 10.3.0.0, before 10.4.0.3 (fixed in 10.4.0.3); version 10.5.0.0 only
- HP Instantos: from 6.4.0.0, before 8.6.0.23 (fixed in 8.6.0.23); from 8.10.0.0, before 8.10.0.9 (fixed in 8.10.0.9); from 8.11.0.0, before 8.11.2.0 (fixed in 8.11.2.0)
Published 2023-11-14. Last modified 2026-06-17.