{"api_version":"v1","generated_at":"2026-10-10T08:45:00+00:00","product":{"cve_count":51,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-hewlett-packard-enterprise-hpe-aruba-mobility-conductor-formerly-mobility-master-aruba-mobility-controllers-wl-3e8c96665eaf","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central","next_cursor":"djE6NTA","observations":[{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33518","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33518","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T02:36:03.419Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T16:35:09.048Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33517","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33517","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOSbranches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T02:36:04.200Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T16:33:15.277Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33516","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33516","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOSbranches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T02:36:04.056Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T16:30:59.727Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33515","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33515","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOSbranches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T02:36:03.488Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T16:28:23.709Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33514","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33514","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS-branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T02:36:02.826Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T16:27:00.666Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33513","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33513","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS-branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-08-27T21:06:32.137Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T16:13:10.629Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33512","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33512","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS-branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T02:36:03.751Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T14:57:08.377Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-33511","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-33511","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS-branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T02:36:03.443Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T14:54:17.968Z"},{"affected":"Aruba Mobility Conductor (formerly Mobility Master); Aruba Mobility Controllers; WLAN Gateways and SD-WAN Gateways managed by Aruba Central: ArubaOS 10.5.x.x: 10.5.1.0 and below, ArubaOS 10.4.x.x: 10.4.1.0 and below, ArubaOS 8.11.x.x: 8.11.2.1 and below, ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-26305","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-26305","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS-branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T00:07:19.370Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T14:52:41.916Z"},{"affected":"ArubaOS 10.5.x.x: 10.5.1.0 and below; ArubaOS 10.4.x.x: 10.4.1.0 and below; ArubaOS 8.11.x.x: 8.11.2.1 and below; ArubaOS 8.10.x.x: 8.10.0.10 and below","affected_versions_present":true,"cve_id":"CVE-2024-26304","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-26304","fixed":"Upgrade Mobility Controllers, Mobility Conductors and Gateways to one of the following AOS versions (as applicable) to resolve all the vulnerabilities described in the details section: AOS-10.6.x.x: 10.6.0.0 and above AOS-10.5.x.x: 10.5.1.1 and above AOS-10.4.x.x: 10.4.1.1 and above AOS-8.12.x.x: 8.12.0.0 and above AOS-8.11.x.x: 8.11.2.2 and above AOS-8.10.x.x: 8.10.0.12 and above NOTE: At the time of publishing of this Revision-3 of the Security Advisory, following AOS software release trains have reached their End of Maintenance (EoM) milestone: AOS 10.6.x.x : all AOS-10.5.x.x : all AOS-8.11.x.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS-branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2024-08-02T00:07:19.227Z","patch_url":"https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-004.json","primary_source":"","published":"2024-05-01T14:43:12.761Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35979","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35979","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-04T15:36:27.642Z","patch_url":"","primary_source":"","published":"2023-07-05T14:50:10.736Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35978","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35978","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-21T21:11:25.552Z","patch_url":"","primary_source":"","published":"2023-07-05T14:49:00.807Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35977","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35977","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-04T15:38:20.007Z","patch_url":"","primary_source":"","published":"2023-07-05T14:47:46.596Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35976","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35976","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-04T15:39:11.162Z","patch_url":"","primary_source":"","published":"2023-07-05T14:47:43.236Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35975","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35975","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-04T15:39:41.143Z","patch_url":"","primary_source":"","published":"2023-07-05T14:46:49.679Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35974","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35974","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-04T15:40:07.015Z","patch_url":"","primary_source":"","published":"2023-07-05T14:45:43.215Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35973","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35973","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-04T15:40:45.590Z","patch_url":"","primary_source":"","published":"2023-07-05T14:45:39.756Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35972","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35972","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-04T15:41:16.557Z","patch_url":"","primary_source":"","published":"2023-07-05T14:44:42.156Z"},{"affected":"- ArubaOS 10.4.x.x: 10.4.0.1 and below; - ArubaOS 8.11.x.x: 8.11.1.0 and below; - ArubaOS 8.10.x.x: 8.10.0.6 and below; - ArubaOS 8.6.x.x: 8.6.0.20 and below","affected_versions_present":true,"cve_id":"CVE-2023-35971","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-35971","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-21T21:11:32.335Z","patch_url":"","primary_source":"","published":"2023-07-05T14:43:11.546Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22778","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22778","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:42:49.528Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T17:05:56.186Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22777","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22777","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:43:18.940Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T17:04:20.522Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22776","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22776","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:43:45.356Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T17:02:51.772Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22775","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22775","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:44:09.561Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:58:34.249Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22774","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22774","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:44:36.045Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:57:05.728Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22773","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22773","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:45:09.674Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:56:44.883Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22772","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22772","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:45:37.808Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:55:26.690Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22771","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22771","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T18:00:34.497Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:53:19.915Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22770","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22770","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T18:01:36.781Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:51:02.255Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22769","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22769","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T18:02:27.462Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:50:46.657Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22768","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22768","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T18:03:15.479Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:49:39.531Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22767","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22767","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-11T14:22:01.847Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:49:03.354Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22766","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22766","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-11T14:24:04.511Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:48:00.530Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22765","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22765","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-11T14:05:33.089Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:47:35.008Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22764","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22764","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-11T14:06:12.703Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:47:14.005Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22763","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22763","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-11T14:06:43.130Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:46:58.281Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22762","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22762","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-12T16:21:36.582Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:46:03.890Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22761","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22761","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T18:05:12.964Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:42:41.162Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22760","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22760","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-12T16:21:55.798Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:42:04.666Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22759","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22759","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T18:06:32.178Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:41:28.980Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22758","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22758","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T18:07:58.897Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:40:37.916Z"},{"affected":"ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22757","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22757","fixed":"Please note that due the complexity of code changes involved it was not possible to backport changes for these specific vulnerabilities (CVE-2023-22753, CVE-2023-22754, CVE-2023-22755, CVE-2023-22756, CVE-2023-22757) to ArubaOS 8.6.x. Customers using firmware versions in the 8.6.x branch are urged to implement the workaround listed in this section or to upgrade to ArubaOS 8.10.x.","last_modified":"2025-03-07T18:09:19.826Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:36:54.386Z"},{"affected":"ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22756","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22756","fixed":"Please note that due the complexity of code changes involved it was not possible to backport changes for these specific vulnerabilities (CVE-2023-22753, CVE-2023-22754, CVE-2023-22755, CVE-2023-22756, CVE-2023-22757) to ArubaOS 8.6.x. Customers using firmware versions in the 8.6.x branch are urged to implement the workaround listed in this section or to upgrade to ArubaOS 8.10.x.","last_modified":"2025-03-07T18:10:01.599Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:36:32.538Z"},{"affected":"ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22755","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22755","fixed":"Please note that due the complexity of code changes involved it was not possible to backport changes for these specific vulnerabilities (CVE-2023-22753, CVE-2023-22754, CVE-2023-22755, CVE-2023-22756, CVE-2023-22757) to ArubaOS 8.6.x. Customers using firmware versions in the 8.6.x branch are urged to implement the workaround listed in this section or to upgrade to ArubaOS 8.10.x.","last_modified":"2025-03-07T18:10:42.680Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:35:24.079Z"},{"affected":"ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22754","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22754","fixed":"Please note that due the complexity of code changes involved it was not possible to backport changes for these specific vulnerabilities (CVE-2023-22753, CVE-2023-22754, CVE-2023-22755, CVE-2023-22756, CVE-2023-22757) to ArubaOS 8.6.x. Customers using firmware versions in the 8.6.x branch are urged to implement the workaround listed in this section or to upgrade to ArubaOS 8.10.x.","last_modified":"2025-03-07T18:11:24.957Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:34:48.324Z"},{"affected":"ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22753","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22753","fixed":"Please note that due the complexity of code changes involved it was not possible to backport changes for these specific vulnerabilities (CVE-2023-22753, CVE-2023-22754, CVE-2023-22755, CVE-2023-22756, CVE-2023-22757) to ArubaOS 8.6.x. Customers using firmware versions in the 8.6.x branch are urged to implement the workaround listed in this section or to upgrade to ArubaOS 8.10.x.","last_modified":"2025-03-11T14:07:56.369Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:33:36.424Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22752","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22752","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-11T14:08:57.916Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:30:06.487Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22751","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22751","fixed":"PLEASE NOTE - To fully patch all the vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above NOTE: At the time of publishing of this Revision-4 of the Security Advisory, following AOS software release trains their End of Maintenance (EoM) milestone: - AOS-8.6.x.x : all - AOS-8.11.x.x : all - AOS-10.3.x.x : all - AOS-10.5.x.x : all - AOS 10.6.x.x : all - SD-Branch 8.7.0.0-2.3.0.x : all Software versions with resolution/fixes for the vulnerabilities covered above can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Maintenance (EoM) milestone. For Software Release End of Life information, visit: https://networkingsupport.hpe.com/notifications;notificationPageSize=100 ;notificationSortBy=announcementDate;notificationSortDir=desc;notificationCategory=Software%20Release%20End%20of%20Life;","last_modified":"2025-03-07T20:46:05.021Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:28:42.105Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22750","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22750","fixed":"PLEASE NOTE - To fully patch the unauthenticated buffer overflow vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit: https://www.arubanetworks.com/support-services/end-of-life/","last_modified":"2025-03-07T20:47:28.814Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:09:16.831Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22749","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22749","fixed":"PLEASE NOTE - To fully patch the unauthenticated buffer overflow vulnerabilities disclosed above customers must upgrade to the following versions: - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above Customers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit: https://www.arubanetworks.com/support-services/end-of-life/","last_modified":"2025-03-07T20:48:40.497Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T16:05:47.658Z"},{"affected":"ArubaOS 8.6.x.x: 8.6.0.19 and below; ArubaOS 8.10.x.x: 8.10.0.4 and below; ArubaOS 10.3.x.x: 10.3.1.0 and below; SD-WAN 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.8 and below","affected_versions_present":true,"cve_id":"CVE-2023-22748","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-22748","fixed":"PLEASE NOTE - To fully patch the unauthenticated buffer overflow vulnerabilities disclosed above customers must upgrade to AOS-8.12 and enable CPSec. See https://www.arubanetworks.com/techdocs/ArubaOS_8.12.0_Web_Help/Content/arubaos-solutions/controlplane/cpsec.htmCustomers who choose to implement the workarounds listed in the Workaround section below should note that all other vulnerabilities listed in this document are addressed by the following versions: - AOS-8.6.x.x: 8.6.0.20 and above - please note that not all issues are fixed in 8.6.x.x. See the Details section above for specific information - AOS-8.10.x.x: 8.10.0.5 and above - AOS-8.11.x.x: 8.11.0.0 and above - AOS-10.3.x.x: 10.3.1.1 and above - SD-Branch 8.7.0.0-2.3.0.x: 8.7.0.0-2.3.0.9 and above HPE Aruba Networking does not evaluate or patch AOS branches that have reached their End of Support (EoS) milestone. For more information about Aruba's End of Support policy visit: https://www.arubanetworks.com/support-services/end-of-life/","last_modified":"2025-03-07T21:04:02.055Z","patch_url":"https://csaf.arubanetworking.hpe.com/2023/hpe_aruba_networking_-_2023-002.json","primary_source":"","published":"2023-02-28T15:59:17.666Z"}],"source_generated_at":"2026-10-10T06:21:41.304Z","vendor":"Hewlett Packard Enterprise (HPE)"}}
