First published: Tue Jan 28 2025(Updated: )
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Aruba Networking Fabric Composer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23056 is considered a significant security vulnerability as it allows for stored cross-site scripting (XSS) attacks.
To fix CVE-2025-23056, it is essential to apply the latest security patches and updates provided by HPE for the Aruba Networking Fabric Composer.
CVE-2025-23056 affects users of HPE Aruba Networking Fabric Composer who have access to the web management interface.
CVE-2025-23056 is associated with stored cross-site scripting (XSS) attacks, allowing attackers to run arbitrary script code.
Yes, CVE-2025-23056 requires an authenticated remote attacker to exploit the vulnerability.