CVE-2019-5320

Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Cross Site Scripting in the web UI, leading to injection of code.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
hpeCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
VendorProductVersion
arubanetworks5400r_firmware
16.08.0 ≤
𝑥
< 16.08.0009
arubanetworks5400r_firmware
16.09.0 ≤
𝑥
< 16.09.0007
arubanetworks5400r_firmware
16.10.0 ≤
𝑥
< 16.10.0003
arubanetworks3810_firmware
16.08.0 ≤
𝑥
< 16.08.0009
arubanetworks3810_firmware
16.09.0 ≤
𝑥
< 16.09.0007
arubanetworks3810_firmware
16.10.0 ≤
𝑥
< 16.10.0003
arubanetworks2920_firmware
16.08.0 ≤
𝑥
< 16.08.0009
arubanetworks2920_firmware
16.09.0 ≤
𝑥
< 16.09.0007
arubanetworks2920_firmware
16.10.0 ≤
𝑥
< 16.10.0003
arubanetworks2930_firmware
16.08.0 ≤
𝑥
< 16.08.0009
arubanetworks2930_firmware
16.09.0 ≤
𝑥
< 16.09.0007
arubanetworks2930_firmware
16.10.0 ≤
𝑥
< 16.10.0003
arubanetworks2530_firmware
16.08.0 ≤
𝑥
< 16.08.0009
arubanetworks2530_firmware
16.09.0 ≤
𝑥
< 16.09.0007
arubanetworks2530_firmware
16.10.0 ≤
𝑥
< 16.10.0003
arubanetworks2530_firmware
16.08.0 ≤
𝑥
< 16.08.0009
arubanetworks2530_firmware
16.09.0 ≤
𝑥
< 16.09.0007
arubanetworks2530_firmware
16.10.0 ≤
𝑥
< 16.10.0003
arubanetworks2540_firmware
16.08.0 ≤
𝑥
< 16.08.0009
arubanetworks2540_firmware
16.09.0 ≤
𝑥
< 16.09.0007
arubanetworks2540_firmware
16.10.0 ≤
𝑥
< 16.10.0003
𝑥
= Vulnerable software versions