PT-2023-18699 · Aruba · Aruba Instant+1
Zack Colgan
·
Published
2023-05-08
·
Updated
2023-05-12
·
CVE-2023-22791
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Aruba InstantOS (affected versions not specified)
ArubaOS 10 (affected versions not specified)
Description
A vulnerability exists where an edge-case combination of network configuration, a specific WLAN environment, and an attacker already possessing valid user credentials on that WLAN can lead to sensitive information being disclosed via the WLAN. The scenarios in which this disclosure of potentially sensitive information can occur are complex and depend on factors that are beyond the control of the attacker.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aruba Instant
Arubaos 10