Vulnerabilities > CVE-2023-22771 - Insufficient Session Expiration vulnerability in Arubanetworks Arubaos and Sd-Wan

047910
CVSS 2.4 - LOW
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
arubanetworks
CWE-613

Summary

An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account

Common Weakness Enumeration (CWE)