vulnerability

Aruba AOS-10: CVE-2023-22791: Aruba InstantOS and ArubaOS 10 Sensitive Information Disclosure

Severity
6
CVSS
(AV:A/AC:M/Au:S/C:C/I:P/A:N)
Published
May 9, 2023
Added
Jan 14, 2025
Modified
Jul 3, 2025

Description

A vulnerability exists in Aruba InstantOS and ArubaOS 10 where an edge-case combination of network configuration, a specific WLAN environment and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of potentially sensitive information can occur are complex and depend on factors that are beyond the control of the attacker.

Solution

aruba-aos-10-cve-2023-22791
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.