← Back

CVE-2023-35971

nvd nist
Published: Jul 5, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A vulnerability in the ArubaOS web-based management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

Affected (4)

1 product
Arubaos
Configuration A
4 vulnerable · 13 platform
Vulnerable SoftwareAffected Versions
Arubanetworks
From 10.4.0.0 to 10.4.0.2
From 6.5.4.0 to 8.6.0.21
From 8.11.0.0 to 8.11.1.1
From 8.7.0.0 to 8.10.0.7
Running on/withPlatform Versions
Arubanetworks
Mc Va 10
All versions
Arubanetworks
Mc Va 1k
All versions
Arubanetworks
Mc Va 250
All versions
Arubanetworks
Mc Va 50
All versions
Arubanetworks
Mcr Hw 10k
All versions
Arubanetworks
Mcr Hw 1k
All versions
Arubanetworks
Mcr Hw 5k
All versions
Arubanetworks
Mcr Va 10k
All versions
Arubanetworks
Mcr Va 1k
All versions
Arubanetworks
Mcr Va 50
All versions
Arubanetworks
Mcr Va 500
All versions
Arubanetworks
Mcr Va 5k
All versions
Arubanetworks
Sd Wan
All versions

References (2)

Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.