GPU VulnDB

Database/Firmware, BMC & network fabric

ArubaOS-Switch web management interface: Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UI

CVE-2023-39266Firmware, BMC & network fabriccurated

Impact

Unauthenticated stored cross-site scripting against the ArubaOS-Switch web UI. Stored XSS in a switch management interface is a credential-theft and config-change path aimed at your network operators: an attacker plants the payload without logging in, and it fires the next time an admin opens the page.

Who can reach it

Unauthenticated, remote to the switch's web management interface; the payload executes in an administrator's browser session.

What to do

ArubaOS-Switch firmware upgrade plus reload. Immediate mitigation is a config change: disable the web management interface and manage via SSH/CLI, which most datacenter operators should be doing anyway. Related ArubaOS issue: CVE-2023-35971.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.