CVE-2023-30509

Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of these vulnerabilities result in the ability to read arbitrary files on the underlying operating system, including sensitive system files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*
cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*

History

07 Jul 2023, 15:15

Type Values Removed Values Added
References
  • {'url': 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt', 'name': 'https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt', 'tags': ['Broken Link', 'Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-007.txt -

25 May 2023, 15:42

Type Values Removed Values Added
First Time Arubanetworks
Arubanetworks edgeconnect Enterprise
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:arubanetworks:edgeconnect_enterprise:*:*:*:*:*:*:*:*
CWE CWE-22
References (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt - (MISC) https://www.arubanetworks.com/assets/alert/ARUBA-PSA-2023-0007.txt - Broken Link, Vendor Advisory

16 May 2023, 20:04

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-16 19:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-30509

Mitre link : CVE-2023-30509

CVE.ORG link : CVE-2023-30509


JSON object : View

Products Affected

arubanetworks

  • edgeconnect_enterprise
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')