5.3

CVE-2022-37909

Aruba has identified certain configurations of ArubaOS that can lead to sensitive information disclosure from the configured ESSIDs. The scenarios in which disclosure of potentially sensitive information can occur are complex, and depend on factors beyond the control of attackers.

Data is provided by the National Vulnerability Database (NVD)
ArubanetworksSd-wan Version >= 8.7.0.0-2.3.0.0 < 8.7.0.0-2.3.0.6
ArubanetworksArubaos Version >= 6.5.4.0 < 6.5.4.22
ArubanetworksArubaos Version >= 8.4.0.0 < 8.6.0.17
ArubanetworksArubaos Version >= 8.7.0.0 < 8.7.1.9
ArubanetworksArubaos Version >= 8.8.0.0 < 10.3.0.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.294
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 1.6 3.6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
security-alert@hpe.com 5.3 1.6 3.6
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.