← Back

CVE-2023-39266

nvd nist
Published: Aug 29, 2023Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.

Affected (5)

Products: Hpe: Arubaos Switch
1 product
Arubaos Switch
Configuration A
5 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Hpe
Before a.15.16.0026
From 16.01.0000 to 16.04.0027
From 16.05.0000 to 16.08.0027
From 16.10.0001 to 16.10.0024
From 16.11.0001 to 16.11.0013
Running on/withPlatform Versions
Arubanetworks
Aruba 2530
All versions
Arubanetworks
Aruba 2530ya
All versions
Arubanetworks
Aruba 2530yb
All versions
Arubanetworks
Aruba 2540
All versions
Arubanetworks
Aruba 2920
All versions
Arubanetworks
Aruba 2930f
All versions
Arubanetworks
Aruba 2930m
All versions
Arubanetworks
Aruba 3810m
All versions
Arubanetworks
Aruba 5406r Zl2
All versions
Arubanetworks
Aruba 5412r Zl2
All versions

References (2)

Source: security-alert@hpe.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.