A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
CVSS Details
- CVSS 3.1 Base Score: 8.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aruba Aos S | — | To address the vulnerabilities described above for the
affected release branches, it is recommended to upgrade the software
to the following versions:
- ArubaOS-Switch 16.11.xxxx: KB/WC/YA/YB/YC.16.11.0013 and above.
- ArubaOS-Switch 16.10.xxxx: WB.16.10.0024 and above.
- ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0027 and above.
- ArubaOS-Switch 16.04.xxxx: KA/RA.16.04.0027 and above.
- ArubaOS-Switch 15.xx.xxxx: A.15.16.0026 and above.
Note: 16.10.xxxx:KB/WC/YA/YB/YC will not receive fixes for these vulnerabilities. Upgrading to KB/WC/YA/YB/YC.16.11.0013 and above will address these vulnerabilities.
The software versions listed in the Resolution section are the supported branches as of the publication date of this advisory. | Mar 6, 2025 | Aug 29, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub