CVE-2023-30507: Authenticated Remote Path Traversal in Aruba EdgeConnect Enterprise Command Line Interface
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30507?
CVE-2023-30507 has a high severity rating due to the potential for unauthorized access to sensitive files.
How do I fix CVE-2023-30507?
To fix CVE-2023-30507, upgrade Aruba EdgeConnect Enterprise to the latest version that addresses the identified vulnerabilities.
What systems are affected by CVE-2023-30507?
CVE-2023-30507 affects Aruba EdgeConnect Enterprise versions up to and including 9.0.8.0, as well as certain 9.1.x and 9.2.x versions.
What are the consequences of exploiting CVE-2023-30507?
Exploiting CVE-2023-30507 could allow an attacker to read arbitrary files on the underlying operating system, potentially exposing sensitive data.
Is authentication required to exploit CVE-2023-30507?
Yes, CVE-2023-30507 can be exploited by authenticated users who have access to the command line interface.