CVE-2022-37911 — XML External Entity (XXE) Injection in Arubaos
Severity
5.5MEDIUMNVD
CNA3.8
EPSS
0.3%
top 43.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 12
Description
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allow an authenticated attacker to retrieve files from the local system or cause the application to consume system resources, resulting in a denial of service condition.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:HExploitability: 1.2 | Impact: 4.2
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-2fwm-fp55-mv7p: Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS↗2022-12-12
CVEList▶
CVE-2022-37911: Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS↗2022-11-03