HIGH
Unauthenticated Stored Cross-Site Scripting (XSS) in ArubaOS Web-based Management Interface
Published Jul 5, 2023
8.8
HIGHCVSS 3.1
EPSS 0.62%
Description
A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected products
-
- Version - ArubaOS 10.4.x.x: 10.4.0.1 and belowStatusaffectedConstraints-
- Version - ArubaOS 8.10.x.x: 8.10.0.6 and belowStatusaffectedConstraints-
- Version - ArubaOS 8.11.x.x: 8.11.1.0 and belowStatusaffectedConstraints-
- Version - ArubaOS 8.6.x.x: 8.6.0.20 and belowStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | n/a | affected |
|
AND
OR
- ≥ 6.5.4.0 · < 8.6.0.21
- ≥ 8.7.0.0 · < 8.10.0.7
- ≥ 8.11.0.0 · < 8.11.1.1
- ≥ 10.4.0.0 · < 10.4.0.2
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-39955 Advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-39955 | Advisory | |
| https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hpe
Published Jul 5, 2023
Updated Oct 21, 2024
Reserved Jun 20, 2023
Link CVE-2023-35971
CISA Vulnrichment
Updated Oct 21, 2024
ENISA EUVD
EUVD-2023-39955 Assigner hpe
Published Jul 5, 2023
Updated Oct 21, 2024
Exploited since n/a
Link EUVD-2023-39955