CVE-2023-22777

EUVD-2023-26895
An authenticated information disclosure vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to read arbitrary files in the underlying operating system.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
hpeCNA
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 54%
Affected Products (NVD)
VendorProductVersion
arubanetworkssd-wan
8.7.0.0-2.3.0.0 ≤
𝑥
≤ 8.7.0.0-2.3.0.8
arubanetworksarubaos
8.6.0.0 ≤
𝑥
≤ 8.6.0.19
arubanetworksarubaos
8.10.0.0 ≤
𝑥
≤ 8.10.0.4
arubanetworksarubaos
10.3.0.0 ≤
𝑥
≤ 10.3.1.0
𝑥
= Vulnerable software versions