Vulnerabilities > Arubanetworks

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2022-43525 Cross-site Scripting vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
arubanetworks CWE-79
6.1
2023-01-05 CVE-2022-43526 Cross-site Scripting vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
arubanetworks CWE-79
6.1
2023-01-05 CVE-2022-43527 Cross-site Scripting vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator
Multiple vulnerabilities within the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow a remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.
network
low complexity
arubanetworks CWE-79
6.1
2023-01-05 CVE-2022-43528 Unspecified vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator
Under certain configurations, an attacker can login to Aruba EdgeConnect Enterprise Orchestrator without supplying a multi-factor authentication code.
network
low complexity
arubanetworks
6.5
2023-01-05 CVE-2022-43529 Session Fixation vulnerability in Arubanetworks Aruba Edgeconnect Enterprise Orchestrator
A vulnerability in the web-based management interface of Aruba EdgeConnect Enterprise Orchestrator could allow an remote attacker to persist a session after a password reset or similar session clearing event.
network
low complexity
arubanetworks CWE-384
5.4
2023-01-05 CVE-2022-43530 SQL Injection vulnerability in Arubanetworks Clearpass Policy Manager
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance.
network
low complexity
arubanetworks CWE-89
8.8
2023-01-05 CVE-2022-43531 SQL Injection vulnerability in Arubanetworks Clearpass Policy Manager
Vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance.
network
low complexity
arubanetworks CWE-89
8.8
2023-01-05 CVE-2022-43532 Cross-site Scripting vulnerability in Arubanetworks Clearpass Policy Manager
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface.
network
low complexity
arubanetworks CWE-79
4.8
2023-01-05 CVE-2022-43533 Unspecified vulnerability in Arubanetworks Clearpass Policy Manager
A vulnerability in the ClearPass OnGuard macOS agent could allow malicious users on a macOS instance to elevate their user privileges.
local
low complexity
arubanetworks
7.8
2023-01-05 CVE-2022-43534 Unspecified vulnerability in Arubanetworks Clearpass Policy Manager
A vulnerability in the ClearPass OnGuard Linux agent could allow malicious users on a Linux instance to elevate their user privileges.
local
low complexity
arubanetworks
7.8