CVE-2019-5322
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. The vulnerability allows an attacker to retrieve sensitive system information. This attack can be carried out without user authentication under very specific conditions.
Published:Feb 12, 2020
Last Modified:Nov 21, 2024
EPS:Feb 12, 2020
EPSS Score:0.00372
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Arubanetworks
Product
2530 10\/100 Port
Arubanetworks
2530 10\/100 Port
Vendor
Arubanetworks
Product
2530 10\/100 Port Firmware
Arubanetworks
2530 10\/100 Port Firmware
Vendor
Arubanetworks
Product
2530 With Gigt Port
Arubanetworks
2530 With Gigt Port
Vendor
Arubanetworks
Product
2530 With Gigt Port Firmware
Arubanetworks
2530 With Gigt Port Firmware
Vendor
Arubanetworks
Product
2540
Arubanetworks
2540
Vendor
Arubanetworks
Product
2540 Firmware
Arubanetworks
2540 Firmware
Vendor
Arubanetworks
Product
2920
Arubanetworks
2920
Vendor
Arubanetworks
Product
2920 Firmware
Arubanetworks
2920 Firmware
Vendor
Arubanetworks
Product
2930
Arubanetworks
2930
Vendor
Arubanetworks
Product
2930 Firmware
Arubanetworks
2930 Firmware
Vendor
Arubanetworks
Product
3810
Arubanetworks
3810
Vendor
Arubanetworks
Product
3810 Firmware
Arubanetworks
3810 Firmware
Vendor
Arubanetworks
Product
5400r
Arubanetworks
5400r
Vendor
Arubanetworks
Product
5400r Firmware
Arubanetworks
5400r Firmware
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
