← Back

CVE-2018-7064

nvd nist
Published: May 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A reflected cross-site scripting (XSS) vulnerability is present in an unauthenticated Aruba Instant web interface. An attacker could use this vulnerability to trick an IAP administrator into clicking a link which could then take administrative actions on the Instant cluster, or expose the session cookie for an administrative session. Workaround: Administrators should make sure they log out of the Aruba Instant UI when not actively managing the system, and should use caution clicking links from external sources while logged into the IAP administrative interface. Resolution: Fixed in Aruba Instant 4.2.4.12, 6.5.4.11, 8.3.0.6, and 8.4.0.0

Affected (5)

1 product
Aruba Instant
1 product
Scalance W1750d Firmware
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Arubanetworks
From 4.0 to 4.2.4.12
From 6.5.0 to 6.5.4.11
From 8.3.0 to 8.3.0.6
From 8.4.0 to 8.4.0.1
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 8.4.0.1
Running on/withPlatform Versions
Siemens
Scalance W1750d
All versions

References (6)

Source: security-alert@hpe.com
Third Party AdvisoryVDB Entry
Source: security-alert@hpe.com
PatchThird Party Advisory
Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.