{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-30504","assignerOrgId":"eb103674-0d28-4225-80f8-39fb86215de0","state":"PUBLISHED","assignerShortName":"hpe","dateReserved":"2023-04-11T20:22:08.184Z","datePublished":"2023-05-16T18:51:43.801Z","dateUpdated":"2025-01-22T21:17:29.095Z"},"containers":{"cna":{"affected":[{"defaultStatus":"affected","product":"Aruba EdgeConnect Enterprise Software","vendor":"Hewlett Packard Enterprise (HPE)","versions":[{"lessThanOrEqual":"9.2.3.0","status":"affected","version":"ECOS 9.2.x.x","versionType":"custom"},{"lessThanOrEqual":"all","status":"affected","version":"ECOS 9.1.x.x","versionType":"custom"},{"lessThanOrEqual":"9.0.8.0","status":"affected","version":"ECOS 9.0.x.x","versionType":"custom"},{"lessThanOrEqual":"all","status":"affected","version":"ECOS 8.x.x.x","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","user":"00000000-0000-4000-9000-000000000000","value":"  Daniel Jensen (@dozernz)"}],"datePublic":"2023-05-23T20:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Vulnerabilities exist in the Aruba EdgeConnect Enterprise&nbsp;command line interface that allow remote authenticated users&nbsp;to run arbitrary commands on the underlying host. Successful&nbsp;exploitation of these vulnerabilities result in the ability&nbsp;to execute arbitrary commands as root on the underlying&nbsp;operating system leading to complete system compromise."}],"value":"Vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface that allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as root on the underlying operating system leading to complete system compromise."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"orgId":"eb103674-0d28-4225-80f8-39fb86215de0","shortName":"hpe","dateUpdated":"2023-07-07T14:30:20.990Z"},"references":[{"url":"https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-007.txt"}],"source":{"discovery":"UNKNOWN"},"title":"Authenticated Remote Code Execution in Aruba EdgeConnect Enterprise Command Line Interface","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T14:28:51.087Z"},"title":"CVE Program Container","references":[{"url":"https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-007.txt","tags":["x_transferred"]}]},{"problemTypes":[{"descriptions":[{"type":"CWE","lang":"en","description":"CWE-noinfo Not enough information"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-01-22T21:17:26.261761Z","id":"CVE-2023-30504","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-01-22T21:17:29.095Z"}}]}}