First published: Tue Jan 28 2025(Updated: )
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Aruba Networking Fabric Composer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23055 is considered a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2025-23055, ensure that you apply the latest patches and updates provided by HPE for the Aruba Networking Fabric Composer.
CVE-2025-23055 affects users of HPE Aruba Networking Fabric Composer who utilize the web management interface.
CVE-2025-23055 allows an authenticated remote attacker to conduct stored cross-site scripting (XSS) attacks.
If CVE-2025-23055 is successfully exploited, a threat actor could execute arbitrary script code in a victim's web browser.