6.5
CVE-2023-22777
- EPSS 0.12%
- Published 01.03.2023 08:15:14
- Last modified 07.03.2025 21:15:14
- Source security-alert@hpe.com
- Teams watchlist Login
- Open Login
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.
Data is provided by the National Vulnerability Database (NVD)
Arubanetworks ≫ Sd-wan Version >= 8.7.0.0-2.3.0.0 <= 8.7.0.0-2.3.0.8
Arubanetworks ≫ Arubaos Version >= 8.6.0.0 <= 8.6.0.19
Arubanetworks ≫ Arubaos Version >= 8.10.0.0 <= 8.10.0.4
Arubanetworks ≫ Arubaos Version >= 10.3.0.0 <= 10.3.1.0
02.03.2023: CERT.at Warnung
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.12% | 0.282 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
security-alert@hpe.com | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.