Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.
2022-12-12T13:15:13.383
2025-05-02T19:15:52.733
Modified
CVSSv3.1: 3.8 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | arubanetworks | sd-wan | < 8.7.0.0-2.3.0.6 | Yes |
Operating System | arubanetworks | arubaos | < 6.5.4.22 | Yes |
Operating System | arubanetworks | arubaos | < 8.6.0.17 | Yes |
Operating System | arubanetworks | arubaos | < 8.7.1.9 | Yes |
Operating System | arubanetworks | arubaos | < 10.3.0.1 | Yes |