Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-23679
HistorySep 06, 2022 - 6:15 p.m.

Cross site request forgery (csrf)

2022-09-0618:15:00
PRIOn knowledge base
www.prio-n.com
4
aos-cx
anti-csrf
command execution
security vulnerability
arubaos-cx switches
upgrade
nvd

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.1%

AOS-CX lacks Anti-CSRF protections in place for state-changing operations. This can potentially be exploited by an attacker to execute commands in the context of another user in ArubaOS-CX Switches version(s): AOS-CX 10.10.xxxx: 10.10.0002 and below, AOS-CX 10.09.xxxx: 10.09.1020 and below, AOS-CX 10.08.xxxx: 10.08.1060 and below, AOS-CX 10.06.xxxx: 10.06.0200 and below. Aruba has released upgrades for ArubaOS-CX Switch Devices that address this security vulnerability.

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.1%

Related for PRION:CVE-2022-23679