CVE-2023-30510
Authenticated Server-side Request Forgery in Aruba EdgeConnect Enterprise Web Management Interface
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data due to the network position of the Aruba EdgeConnect Enterprise instance.
A vulnerability exists in the Aruba EdgeConnect Enterprise web management interface that allows remote authenticated users to issue arbitrary URL requests from the Aruba EdgeConnect Enterprise instance. The impact of this vulnerability is limited to a subset of URLs which can result in the possible disclosure of data due to the network position of the Aruba EdgeConnect Enterprise instance.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-04-11 CVE Reserved
- 2023-05-16 CVE Published
- 2025-01-22 CVE Updated
- 2025-04-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Arubanetworks Search vendor "Arubanetworks" | Edgeconnect Enterprise Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" | <= 9.0.8.0 Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" and version " <= 9.0.8.0" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Edgeconnect Enterprise Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" | >= 9.1.0.0 <= 9.1.5.0 Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" and version " >= 9.1.0.0 <= 9.1.5.0" | - |
Affected
| ||||||
Arubanetworks Search vendor "Arubanetworks" | Edgeconnect Enterprise Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" | >= 9.2.0.0 <= 9.2.3.0 Search vendor "Arubanetworks" for product "Edgeconnect Enterprise" and version " >= 9.2.0.0 <= 9.2.3.0" | - |
Affected
|