4.8

CVE-2022-28624

A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE FlexFabric 5945_7.10.R6635.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Flexnetwork 5130 Ei Firmware Version 7.10.r3507p02
   Hpe ≫ Flexnetwork 5130 Ei Version -
Hpe ≫ Flexfabric 5945 Firmware Version 7.10.r6635
   Hpe ≫ Flexfabric 5945 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.335
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
NIST 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbnw04265en_us
Vendor Advisory