A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.
| Vendor | Product | Versions |
|---|---|---|
| hewlett packard enterprise (hpe) | aos-cx | 10.18.0000, 10.17.0000, 10.16.0000, 10.13.0000, 10.10.0000 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| aruba | arubaos | cert_advisory | 90% |
Loading…