CVE-2019-5314Injection in Arubaos

CWE-74Injection3 documents3 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 46.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateMay 24

Description

Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS. An attacker would be able to accomplish this by sending certain URL parameters that would trigger this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDarubanetworks/arubaos6.5.4.06.5.4.11+3
CVEListV5aruba_networks/aruba_mobility_controllersAruba Mobility Controller firmware (ArubaOS) 6.x prior to 6.4.4.21 6.5.x prior to 6.5.4.13 8.x prior to 8.2.2.6 8.3.0.x prior to 8.3.0.7, 8.4.0.x and prior to 8.4.0.3

🔴Vulnerability Details

2
GHSA
GHSA-869g-gwxw-f53m: Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS2022-05-24
CVEList
CVE-2019-5314: Some web components in the ArubaOS software are vulnerable to HTTP Response splitting (CRLF injection) and Reflected XSS2019-09-13
CVE-2019-5314 — Injection in Arubanetworks Arubaos | cvebase