7.5
CVE-2019-5322
- EPSS 0.37%
- Published 13.02.2020 00:15:11
- Last modified 21.11.2024 04:44:44
- Source security-alert@hpe.com
- Teams watchlist Login
- Open Login
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. The vulnerability allows an attacker to retrieve sensitive system information. This attack can be carried out without user authentication under very specific conditions.
Data is provided by the National Vulnerability Database (NVD)
Arubanetworks ≫ 5400r Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks ≫ 5400r Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks ≫ 5400r Firmware Version >= 16.10.0 < 16.10.0003
Arubanetworks ≫ 3810 Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks ≫ 3810 Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks ≫ 3810 Firmware Version >= 16.10.0 < 16.10.0003
Arubanetworks ≫ 2920 Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks ≫ 2920 Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks ≫ 2920 Firmware Version >= 16.10.0 < 16.10.0003
Arubanetworks ≫ 2930 Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks ≫ 2930 Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks ≫ 2930 Firmware Version >= 16.10.0 < 16.10.0003
Arubanetworks ≫ 2530 With Gigt Port Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks ≫ 2530 With Gigt Port Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks ≫ 2530 With Gigt Port Firmware Version >= 16.10.0 < 16.10.0003
Arubanetworks ≫ 2530 10/100 Port Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks ≫ 2530 10/100 Port Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks ≫ 2530 10/100 Port Firmware Version >= 16.10.0 < 16.10.0003
Arubanetworks ≫ 2540 Firmware Version >= 16.08.0 < 16.08.0009
Arubanetworks ≫ 2540 Firmware Version >= 16.09.0 < 16.09.0007
Arubanetworks ≫ 2540 Firmware Version >= 16.10.0 < 16.10.0003
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.37% | 0.581 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|