A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
| Vendor | Product | Versions |
|---|---|---|
| hpe | arubaos-cx | 10.18.0000, 10.17.0000, 10.16.0000, 10.13.0000, 10.10.0000 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| aruba | arubaos | cert_advisory | 90% |
| hpe | aruba_cx_10000-48y6c_\(r8p14a\) | cve_cpe | 95% |
| hpe | aruba_cx_6000_12p_\(s4r21a\) | cve_cpe | 95% |
| hpe | aruba_cx_6000_48p_\(r8n85b\) | cve_cpe | 95% |
| hpe | aruba_cx_6100_12g_\(jl679a\) | cve_cpe | 95% |
Loading…