CVE-2022-37911

⚪ Do wiadomości

Nieprawidłowe ograniczenia w ArubaOS umożliwiają atakującemu dostęp do plików i DoS.

CVSS
3.8
EPSS
0.6%
Exploit
none
Vendor
arubanetworks
Opis źródłowy (NVD)

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.

dos Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS3.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2022-12-12 13:15:13 UTC
Ostatnia modyfikacja (NVD)2026-10-08 17:14:21 UTC
Referencje