CVE-2023-39266: Unauthenticated Stored Cross-Site Scripting in ArubaOS-Switch
A vulnerability in the ArubaOS-Switch web management interface could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface provided certain configuration options are present. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39266?
CVE-2023-39266 is a vulnerability in the ArubaOS-Switch web management interface that could allow an unauthenticated remote attacker to conduct a stored cross-site scripting (XSS) attack.
How can an attacker exploit CVE-2023-39266?
An attacker can exploit CVE-2023-39266 by sending malicious input to the web management interface, which is not properly validated and stored
What is the severity of CVE-2023-39266?
The severity of CVE-2023-39266 is high with a CVSS score of 6.1
Which version of ArubaOS-Switch is affected by CVE-2023-39266?
ArubaOS-Switch versions a.15.16.0026 up to, but not including, 16.11.0013 are affected by CVE-2023-39266.
Is Aruba 2530 vulnerable to CVE-2023-39266?
No, Aruba 2530 is not vulnerable to CVE-2023-39266.