Vulnerability Details CVE-2023-22778
A vulnerability in the ArubaOS web management interface could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. A successful exploit could allow an attacker to execute arbitrary script code in a victim's browser in the context of the affected interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.0%
CVSS Severity
CVSS v3 Score 4.8
Products affected by CVE-2023-22778
-
cpe:2.3:a:arubanetworks:sd-wan:*
-
cpe:2.3:o:arubanetworks:arubaos:10.3.0.0
-
cpe:2.3:o:arubanetworks:arubaos:10.3.1.0
-
cpe:2.3:o:arubanetworks:arubaos:8.10.0.0
-
cpe:2.3:o:arubanetworks:arubaos:8.6.0.0
-
cpe:2.3:o:arubanetworks:arubaos:8.6.0.11
-
cpe:2.3:o:arubanetworks:arubaos:8.6.0.5
-
cpe:2.3:o:arubanetworks:arubaos:8.6.0.6
-
cpe:2.3:o:arubanetworks:arubaos:8.6.0.7
-
cpe:2.3:o:arubanetworks:arubaos:8.6.0.8
-
cpe:2.3:o:arubanetworks:arubaos:8.6.0.9