CVE-2019-5322
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/02/2020
Last modified:
24/08/2020
Description
A remotely exploitable information disclosure vulnerability is present in Aruba Intelligent Edge Switch models 5400, 3810, 2920, 2930, 2530 with GigT port, 2530 10/100 port, or 2540. The vulnerability impacts firmware 16.08.* before 16.08.0009, 16.09.* before 16.09.0007 and 16.10.* before 16.10.0003. The vulnerability allows an attacker to retrieve sensitive system information. This attack can be carried out without user authentication under very specific conditions.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:* | 16.08.0 (including) | 16.08.0009 (excluding) |
| cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:* | 16.09.0 (including) | 16.09.0007 (excluding) |
| cpe:2.3:o:arubanetworks:5400r_firmware:*:*:*:*:*:*:*:* | 16.10.0 (including) | 16.10.0003 (excluding) |
| cpe:2.3:h:arubanetworks:5400r:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:* | 16.08.0 (including) | 16.08.0009 (excluding) |
| cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:* | 16.09.0 (including) | 16.09.0007 (excluding) |
| cpe:2.3:o:arubanetworks:3810_firmware:*:*:*:*:*:*:*:* | 16.10.0 (including) | 16.10.0003 (excluding) |
| cpe:2.3:h:arubanetworks:3810:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:* | 16.08.0 (including) | 16.08.0009 (excluding) |
| cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:* | 16.09.0 (including) | 16.09.0007 (excluding) |
| cpe:2.3:o:arubanetworks:2920_firmware:*:*:*:*:*:*:*:* | 16.10.0 (including) | 16.10.0003 (excluding) |
| cpe:2.3:h:arubanetworks:2920:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:* | 16.08.0 (including) | 16.08.0009 (excluding) |
| cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:* | 16.09.0 (including) | 16.09.0007 (excluding) |
| cpe:2.3:o:arubanetworks:2930_firmware:*:*:*:*:*:*:*:* | 16.10.0 (including) | 16.10.0003 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



