CVE-2022-37911
⚪ Do wiadomości
Nieprawidłowe ograniczenia w ArubaOS umożliwiają atakującemu dostęp do plików i DoS.
CVSS
3.8
EPSS
0.6%
Exploit
none
Vendor
arubanetworks
Opis źródłowy (NVD)
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.
dos
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 3.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2022-12-12 13:15:13 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 17:14:21 UTC |
Referencje
- https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2022-016.txt ([email protected]) [Vendor Advisory]