HPE Aruba Networking AOS-CX
cpe:2.3:o:hpe:arubaos-cx:*:*:*:*:*:*:*
- >= 10.15.0.0, <= 10.15.1000
- >= 10.14.0.0, <= 10.14.1030
- >= 10.13.0.0, <= 10.13.1070
- >= 10.10.0.0, <= 10.10.1140
A vulnerability exists in the AOS-CX software for the HPE Aruba Networking CX 9300 Switch Series, specifically in versions AOS-CX 10.14.xxxx (all patches) and AOS-CX 10.15.xxxx (10.15.1000 and below). This vulnerability allows traffic originating from the CX 9300 switches to bypass Access Control List (ACL) rules on routed ports during egress, leading to improper enforcement of port ACLs. Consequently, this could result in unauthorized traffic flow and breaches of security policies. It is important to note that egress VLAN ACLs and Routed VLAN ACLs are not impacted by this issue.
Exploitation of this vulnerability could cause port ACLs to be incorrectly applied, allowing unauthorized traffic to flow through routed ports on CX 9300 switches, thereby violating established security policies.
To address this vulnerability, HPE Aruba Networking CX 9300 customers should upgrade to AOS-CX 10.15.1005 or higher. For versions 10.14.xxxx, all versions are affected, while for 10.15.xxxx, only versions 10.15.1000 and below are impacted. The updated software can be downloaded from the HPE Networking Support Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.