Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-30510


A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data due to the network position of the Aruba EdgeConnect Enterprise instance.


Published

2023-05-16T19:15:10.140

Last Modified

2024-11-21T08:00:19.323

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.1 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application arubanetworks edgeconnect_enterprise ≤ 9.0.8.0 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.1.5.0 Yes
Application arubanetworks edgeconnect_enterprise ≤ 9.2.3.0 Yes

References