vulnerability
Aruba AOS-10: CVE-2023-22791: Aruba InstantOS and ArubaOS 10 Sensitive Information Disclosure
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 6 | (AV:A/AC:M/Au:S/C:C/I:P/A:N) | May 9, 2023 | Jan 14, 2025 | Jul 3, 2025 |
Severity
6
CVSS
(AV:A/AC:M/Au:S/C:C/I:P/A:N)
Published
May 9, 2023
Added
Jan 14, 2025
Modified
Jul 3, 2025
Description
A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of potentially sensitive information can occur are complex and depend on factors that are beyond the control of the attacker.
Solution
aruba-aos-10-cve-2023-22791
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.