First published: Tue Jan 28 2025(Updated: )
A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface.
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
HPE Aruba Networking Fabric Composer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23057 is considered a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2025-23057, update to the latest version of HPE Aruba Networking Fabric Composer that includes security patches addressing this vulnerability.
CVE-2025-23057 affects users of the HPE Aruba Networking Fabric Composer, particularly those with access to the web management interface.
CVE-2025-23057 is associated with stored cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary script code.
Yes, CVE-2025-23057 can significantly impact network security by allowing malicious scripts to run in the browsers of authenticated users.