MEDIUM
Authenticated Sensitive Information Disclosure in ArubaOS Command Line Interface
Published Jul 5, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.55%
Description
Vulnerabilities exist which allow an authenticated attacker to access sensitive information on the ArubaOS command line interface. Successful exploitation could allow access to data beyond what is authorized by the users existing privilege level.
Affected products
-
Affected
- - ArubaOS 10.4.x.x: 10.4.0.1 and below
- - ArubaOS 8.10.x.x: 8.10.0.6 and below
- - ArubaOS 8.11.x.x: 8.11.1.0 and below
- - ArubaOS 8.6.x.x: 8.6.0.20 and below
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Hewlett Packard Enterprise (HPE) | n/a | affected | Affected
|
AND
OR
- ≥ 6.5.4.0 · < 8.6.0.21
- ≥ 8.7.0.0 · < 8.10.0.7
- ≥ 8.11.0.0 · < 8.11.1.1
- ≥ 10.4.0.0 · < 10.4.0.2
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-39960 Advisory
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-39960 | Advisory | |
| https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-008.txt | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hpe
Published Jul 5, 2023
Updated Dec 4, 2024
Reserved Jun 20, 2023
Link CVE-2023-35976
CISA Vulnrichment
Updated Dec 4, 2024
Red Hat
No data
GitHub
No data