CVE-2019-5320

Aruba Intelligent Edge Switch Series 2540, 2530, 2930F, 2930M, 2920, 5400R, and 3810M with firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007, 16.10.* before 16.10.0003 are vulnerable to Cross Site Scripting in the web UI, leading to injection of code.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:5400r:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:3810:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2920:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2930:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
OR cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2530:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
OR cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2530_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2530:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
OR cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:arubanetworks:2540_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:arubanetworks:2540:-:*:*:*:*:*:*:*

Information

Published : 2020-08-26 16:15

Updated : 2020-09-02 09:09


NVD link : CVE-2019-5320

Mitre link : CVE-2019-5320


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

arubanetworks

  • 5400r_firmware
  • 2530
  • 2540
  • 3810
  • 2540_firmware
  • 2530_firmware
  • 2920_firmware
  • 2930_firmware
  • 2920
  • 2930
  • 5400r
  • 3810_firmware