An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
2023-03-01T08:15:14.473
2025-03-07T21:15:14.620
Modified
CVSSv3.1: 4.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | arubanetworks | arubaos | ≤ 8.6.0.19 | Yes |
Operating System | arubanetworks | arubaos | ≤ 8.10.0.4 | Yes |
Operating System | arubanetworks | arubaos | ≤ 10.3.1.0 | Yes |
Hardware | arubanetworks | 7010 | - | No |
Hardware | arubanetworks | 7030 | - | No |
Hardware | arubanetworks | 7205 | - | No |
Hardware | arubanetworks | 7210 | - | No |
Hardware | arubanetworks | 7220 | - | No |
Hardware | arubanetworks | 7240xm | - | No |
Hardware | arubanetworks | 7280 | - | No |
Hardware | arubanetworks | 9004 | - | No |
Hardware | arubanetworks | 9004-lte | - | No |
Hardware | arubanetworks | 9012 | - | No |
Hardware | arubanetworks | mc-va-10 | - | No |
Hardware | arubanetworks | mc-va-1k | - | No |
Hardware | arubanetworks | mc-va-250 | - | No |
Hardware | arubanetworks | mc-va-50 | - | No |
Hardware | arubanetworks | mcr-hw-10k | - | No |
Hardware | arubanetworks | mcr-hw-1k | - | No |
Hardware | arubanetworks | mcr-hw-5k | - | No |
Hardware | arubanetworks | mcr-va-10k | - | No |
Hardware | arubanetworks | mcr-va-1k | - | No |
Hardware | arubanetworks | mcr-va-50 | - | No |
Hardware | arubanetworks | mcr-va-500 | - | No |
Hardware | arubanetworks | mcr-va-5k | - | No |
Application | arubanetworks | sd-wan | ≤ 8.7.0.0-2.3.0.8 | Yes |