CVE-2023-39266
29.08.2023, 20:15
A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Vendor | Product | Version |
---|---|---|
hpe | arubaos-switch | 16.01.0000 ≤ 𝑥 < 16.04.0027 |
hpe | arubaos-switch | 16.05.0000 ≤ 𝑥 < 16.08.0027 |
hpe | arubaos-switch | 16.10.0001 ≤ 𝑥 < 16.10.0024 |
hpe | arubaos-switch | 16.11.0001 ≤ 𝑥 < 16.11.0013 |
𝑥
= Vulnerable software versions