First published: Tue May 16 2023(Updated: )
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arubanetworks Edgeconnect Enterprise | <=9.0.8.0 | |
Arubanetworks Edgeconnect Enterprise | >=9.1.0.0<=9.1.5.0 | |
Arubanetworks Edgeconnect Enterprise | >=9.2.0.0<=9.2.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-30509 refers to multiple authenticated path traversal vulnerabilities in the Aruba EdgeConnect Enterprise command line interface.
CVE-2023-30509 has a severity level of medium, with a severity score of 6.5.
CVE-2023-30509 affects Aruba EdgeConnect Enterprise versions 9.0.8.0 to 9.2.3.0 (inclusive).
Exploiting CVE-2023-30509 allows attackers to read arbitrary files on the underlying operating system, including sensitive system files.
To fix CVE-2023-30509, it is recommended to update Aruba EdgeConnect Enterprise to a version that has the vulnerability patched.