CVE-2023-38486 HIGH

CVE-2023-38486: Hardware Root of Trust Bypass in 9200 and 9000 Series Controllers and Gateways

Vendor Hewlett Packard Enterprise (Hpe)
Product 9200 Series Mobility Controllers and SD-WAN Gateways, 9000 Series Mobility Controllers and SD-WAN Gateways
Published September 6, 2023
Last update September 26, 2024

CVSS base score

7.7/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series Controllers and Gateways allows an attacker to bypass security controls which would normally prohibit unsigned kernel images from executing. An attacker can use this vulnerability to execute arbitrary runtime operating systems, including unverified and unsigned OS images.

Key dates

02Disclosure timeline

September 6, 2023 CVE published
September 26, 2024 Record updated