7.5

CVE-2019-5322

A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. The vulnerability allows an attacker to retrieve sensitive system information. This attack can be carried out without user authentication under very specific conditions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arubanetworks5400r Firmware Version >= 16.08.0 < 16.08.0009
   Arubanetworks5400r Version-
Arubanetworks5400r Firmware Version >= 16.09.0 < 16.09.0007
   Arubanetworks5400r Version-
Arubanetworks5400r Firmware Version >= 16.10.0 < 16.10.0003
   Arubanetworks5400r Version-
Arubanetworks3810 Firmware Version >= 16.08.0 < 16.08.0009
   Arubanetworks3810 Version-
Arubanetworks3810 Firmware Version >= 16.09.0 < 16.09.0007
   Arubanetworks3810 Version-
Arubanetworks3810 Firmware Version >= 16.10.0 < 16.10.0003
   Arubanetworks3810 Version-
Arubanetworks2920 Firmware Version >= 16.08.0 < 16.08.0009
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.09.0 < 16.09.0007
   Arubanetworks2920 Version-
Arubanetworks2920 Firmware Version >= 16.10.0 < 16.10.0003
   Arubanetworks2920 Version-
Arubanetworks2930 Firmware Version >= 16.08.0 < 16.08.0009
   Arubanetworks2930 Version-
Arubanetworks2930 Firmware Version >= 16.09.0 < 16.09.0007
   Arubanetworks2930 Version-
Arubanetworks2930 Firmware Version >= 16.10.0 < 16.10.0003
   Arubanetworks2930 Version-
Arubanetworks2530 With Gigt Port Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks2530 With Gigt Port Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks2530 With Gigt Port Firmware Version >= 16.10.0 < 16.10.0003
Arubanetworks2530 10/100 Port Firmware Version >= 16.08.0 < 16.08.0009
   Arubanetworks2530 10/100 Port Version-
Arubanetworks2530 10/100 Port Firmware Version >= 16.09.0 < 16.09.0007
   Arubanetworks2530 10/100 Port Version-
Arubanetworks2530 10/100 Port Firmware Version >= 16.10.0 < 16.10.0003
   Arubanetworks2530 10/100 Port Version-
Arubanetworks2540 Firmware Version >= 16.08.0 < 16.08.0009
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.09.0 < 16.09.0007
   Arubanetworks2540 Version-
Arubanetworks2540 Firmware Version >= 16.10.0 < 16.10.0003
   Arubanetworks2540 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.37% 0.581
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N