CVE-2023-22791
08.05.2023, 15:15
A vulnerability exists in Aruba InstantOS and ArubaOS 10where an edge-case combination of network configuration, aspecific WLAN environment and an attacker already possessingvalid user credentials on that WLAN can lead to sensitiveinformation being disclosed via the WLAN. The scenarios inwhich this disclosure of potentially sensitive informationcan occur are complex and depend on factors that are beyondthe control of the attacker.Enginsight
Vendor | Product | Version |
---|---|---|
arubanetworks | arubaos | 10.3.0.0 ≤ 𝑥 ≤ 10.3.1.0 |
hp | instantos | 6.4.0.0 ≤ 𝑥 ≤ 6.4.4.8-4.2.4.20 |
hp | instantos | 6.5.0.0 ≤ 𝑥 ≤ 6.5.4.23 |
hp | instantos | 8.4.0.0 ≤ 𝑥 < 8.6.0.0 |
hp | instantos | 8.6.0.0 ≤ 𝑥 ≤ 8.6.0.19 |
hp | instantos | 8.7.0.0 ≤ 𝑥 ≤ 8.9.0.0 |
hp | instantos | 8.10.0.0 ≤ 𝑥 ≤ 8.10.0.4 |
𝑥
= Vulnerable software versions