A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Successful exploitation of this vulnerability could result in the disclosure of confidential system information, potentially enabling further attacks against the affected device.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.4.0.0, < 10.4.1.11CPE matchmatch criteria | cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* | ||
>= 10.5.0.0, < 10.7.2.3CPE matchmatch criteria | cpe:2.3:o:arubanetworks:arubaos:*:*:*:*:*:*:*:* | ||
10.8.0.0CPE matchmatch criteria | cpe:2.3:o:arubanetworks:arubaos:10.8.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.