Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-39266


A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.


Published

2023-08-29T20:15:09.637

Last Modified

2024-11-21T08:15:01.040

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.3 (HIGH)

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hpe arubaos-switch < a.15.16.0026 Yes
Operating System hpe arubaos-switch < 16.04.0027 Yes
Operating System hpe arubaos-switch < 16.08.0027 Yes
Operating System hpe arubaos-switch < 16.10.0024 Yes
Operating System hpe arubaos-switch < 16.11.0013 Yes
Hardware arubanetworks aruba_2530 - No
Hardware arubanetworks aruba_2530ya - No
Hardware arubanetworks aruba_2530yb - No
Hardware arubanetworks aruba_2540 - No
Hardware arubanetworks aruba_2920 - No
Hardware arubanetworks aruba_2930f - No
Hardware arubanetworks aruba_2930m - No
Hardware arubanetworks aruba_3810m - No
Hardware arubanetworks aruba_5406r_zl2 - No
Hardware arubanetworks aruba_5412r_zl2 - No

References